org.nutz.cloud:nutzcloud-literpc@2.3.8.v20191031 vulnerabilities

  • latest version

    2.5.1.v20220215

  • first published

    6 years ago

  • latest version published

    3 years ago

  • licenses detected

  • package registry

  • Direct Vulnerabilities

    Known vulnerabilities in the org.nutz.cloud:nutzcloud-literpc package. This does not include vulnerabilities belonging to this package’s dependencies.

    Fix vulnerabilities automatically

    Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Deserialization of Untrusted Data

    Affected versions of this package are vulnerable to Deserialization of Untrusted Data via the HttpServletRpcEndpoint endpoint. of the LiteRpc-Serializer component. An attacker can enumerate valid values for LiteRpc-Klass and LiteRpc-Method headers without guessing, guaranteeing that the invocation will reach a real RpcInvoker and the deserialization code path will execute.

    How to fix Deserialization of Untrusted Data?

    There is no fixed version for org.nutz.cloud:nutzcloud-literpc.

    [0,)