Description
xxl-rpc v1.7.0 was discovered to contain a deserialization vulnerability via the component com.xxl.rpc.core.remoting.net.impl.netty.codec.NettyDecode#decode.
Remediation
References
https://github.com/edirc-wong/record/blob/main/deserialization_vulnerability_report.md
Related Vulnerabilities
CVE-2015-0250 Vulnerability in maven package batik:batik-dom
CVE-2023-22491 Vulnerability in npm package gatsby-transformer-remark
CVE-2018-21268 Vulnerability in npm package traceroute
CVE-2017-16195 Vulnerability in npm package pytservce
CVE-2017-16114 Vulnerability in maven package org.webjars.npm:marked