by @jakaba
23 Feb 2024

XXL-RPC RCE (CVE-2023-45146)

by @jakaba
23 Feb 2024

XXL-RPC RCE (CVE-2023-45146)

CVEs

10 Critical Severity

Apps

X
Xxl-RpcXxl-Rpc Project
1.0.1M.*
1.7.0.*
1.4.2.*
1.2.2.*
1.4.0.*
1.3.2.*
1.2.1.*
1.5.0.*
1.2.0.*
1.3.0.*

Screenshots from the blog posts

images/clsw0j62g03t81hn02wdiek9j.jpgimages/clsw0j62g03t81hn02wdiek9j.jpg

Summary

One of the key offerings from the XXL series is XXL-RPC, a high-performance, distributed Remote Procedure Call (RPC) framework. It enables the establishment of TCP servers using the Netty framework and the Hessian serialization mechanism. However, a critical vulnerability has been identified in the XXL-RPC framework, posing a potential threat to systems utilizing this technology.

Description

users/photos/clj8b3h1k16g10uoihwvzgsxi.png

@jakaba

74 posts

Total vcoins

64.3K

Social media links

Comments (1)