漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Apache Fory: Java ReplaceResolverSerializer deserialization checks bypass
Vulnerability Description
Deserialization of Untrusted Data in the Java replace-resolve path in Apache Fory fory-core Java SDK before 1.1.0 on Java/JVM platforms allows a remote attacker to bypass class registration, TypeChecker, and DisallowedList checks and invoke classpath-present readResolve/readExternal hooks via crafted Fory serialized data. Users are recommended to upgrade to version 1.1.0 or later, which fixes this issue.
CVSS Information
N/A
Vulnerability Type
可信数据的反序列化
Vulnerability Title
Apache Fory 安全漏洞
Vulnerability Description
Apache Fory是美国阿帕奇(Apache)基金会的一个序列化框架。 Apache Fory 1.1.0之前版本存在安全漏洞,该漏洞源于Java replace-resolve路径中不可信数据反序列化,可能导致远程攻击者绕过类注册、TypeChecker和DisallowedList检查,并通过特制Fory序列化数据调用类路径中的readResolve/readExternal钩子。
CVSS Information
N/A
Vulnerability Type
N/A