漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
mchange-commons-java contains elements susceptible to abuse via JNDI injection and "deserialization gadgets"
Vulnerability Description
mchange-commons-java is a Java library of shared utility classes used by mchange projects like the c3p0 connection pool. Prior to version 0.6.0, its JNDI ObjectFactory implementation (com.mchange.v2.naming.JavaBeanObjectFactory) will construct objects of arbitrary classes and initialize "JavaBean"-style properties, which for certain classes enables JNDI injection and "deserialization gadgets." Such initialization is unsafe for some classes: for example, setting the contentType property of a Swing JEditorPane to text/html and its text property to HTML containing a stylesheet <link> will provoke an HTTP GET on an arbitrary URL, potentially from within a trusted security domain. The problem is aggravated by the library's ReferenceIndirector, through which malicious JNDI Reference objects can be smuggled in for dereferencing wherever an application reads a Java-serialized object. This has been resolved in version 0.6.0.
CVSS Information
CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
可信数据的反序列化
Vulnerability Title
Steve Waldman mchange-commons-java 代码注入漏洞
Vulnerability Description
Steve Waldman mchange-commons-java是Steve Waldman个人开发者开源的一个软件。 Steve Waldman mchange-commons-java 0.6.0之前版本存在安全漏洞,该漏洞源于JNDI ObjectFactory实现(com.mchange.v2.naming.JavaBeanObjectFactory)会构建任意类的对象并初始化"JavaBean"样式属性,导致JNDI注入和反序列化小工具链被利用,例如设置Swing JEditorPane的c
CVSS Information
N/A
Vulnerability Type
N/A