Description
Deserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.
Remediation
References
https://gitee.com/dromara/hutool/issues/I6AEX2
https://github.com/dromara/hutool/issues/2855
Related Vulnerabilities
CVE-2016-7103 Vulnerability in maven package org.webjars.npm:jquery-ui
CVE-2023-26149 Vulnerability in npm package quill-mention
CVE-2022-1466 Vulnerability in maven package org.keycloak:keycloak-core
CVE-2017-16132 Vulnerability in npm package simple-npm-registry
CVE-2022-31051 Vulnerability in npm package semantic-release