漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Apache Helix: Deserialization vulnerability in Helix workflow and REST
Vulnerability Description
An attacker can use SnakeYAML to deserialize java.net.URLClassLoader and make it load a JAR from a specified URL, and then deserialize javax.script.ScriptEngineManager to load code using that ClassLoader. This unbounded deserialization can likely lead to remote code execution. The code can be run in Helix REST start and Workflow creation. Affect all the versions lower and include 1.2.0. Affected products: helix-core, helix-rest Mitigation: Short term, stop using any YAML based configuration and workflow creation. Long term, all Helix version bumping up to 1.3.0
CVSS Information
N/A
Vulnerability Type
可信数据的反序列化
Vulnerability Title
Apache Helix 代码问题漏洞
Vulnerability Description
Apache Helix是美国阿帕奇(Apache)基金会的一个通用集群管理框架,用于自动管理托管在节点集群上的分区、复制和分布式资源。 Apache Helix 1.2.0版本及之前版本存在代码问题漏洞,该漏洞源于攻击者可以利用SnakeYAML对java.net.URLClassLoader进行反序列化,使其从指定的URL加载JAR,并随后对javax.script.ScriptEngineManager进行反序列化,使用该ClassLoader加载代码。这种不受限制的反序列化可能导致远程代码执行。
CVSS Information
N/A
Vulnerability Type
N/A