First published: Tue Jan 31 2023(Updated: )
Deserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Hutool Hutool | =5.8.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-24162 is a deserialization vulnerability in Dromara Hutool v5.8.11 that allows an attacker to execute arbitrary code.
An attacker can exploit CVE-2023-24162 by using the XmlUtil.readObjectFromXml parameter to execute arbitrary code.
CVE-2023-24162 has a severity rating of critical.
To fix CVE-2023-24162, update Dromara Hutool to version 5.8.12 or later.
CWE-502 refers to the deserialization of untrusted data, which is the underlying issue that allows CVE-2023-24162 to occur.