漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Apache EventMesh RabbitMQ-Connector plugin allows RCE through deserialization of untrusted data
Vulnerability Description
CWE-502 Deserialization of Untrusted Data at the rabbitmq-connector plugin module in Apache EventMesh (incubating) V1.7.0\V1.8.0 on windows\linux\mac os e.g. platforms allows attackers to send controlled message and remote code execute via rabbitmq messages. Users can use the code under the master branch in project repo to fix this issue, we will release the new version as soon as possible.
CVSS Information
N/A
Vulnerability Type
可信数据的反序列化
Vulnerability Title
Apache EventMesh 代码问题漏洞
Vulnerability Description
Apache EventMesh是美国阿帕奇(Apache)基金会的新一代无服务器事件中间件,用于构建分布式事件驱动应用程序。 Apache EventMesh(incubating) V1.7.0至V1.8.0版本存在代码问题漏洞,该漏洞源于rabbitmq-connector plugin模块存在反序列化漏洞。
CVSS Information
N/A
Vulnerability Type
N/A