CVE-2023-48886: Critical severity nettyrpc vulnerability
Published Dec 1, 2023
·Updated
A deserialization vulnerability in NettyRpc v1.2 allows attackers to execute arbitrary commands via sending a crafted RPC request.
Affected Software
1 affected component
Luxiaoxun Nettyrpc=1.2
Event History
Dec 1, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Frequently Asked Questions
1
What is CVE-2023-48886?
CVE-2023-48886 is a deserialization vulnerability in NettyRpc v1.2 that allows attackers to execute arbitrary commands.
2
How can an attacker exploit CVE-2023-48886?
An attacker can exploit CVE-2023-48886 by sending a crafted RPC request.
3
What is the severity of CVE-2023-48886?
CVE-2023-48886 has a severity value of 9.8, indicating it is critical.
4
Is there a fix for CVE-2023-48886?
At the moment, there is no known fix for CVE-2023-48886. It is recommended to follow the official GitHub repository for updates and patches.
5
What is the CWE ID for CVE-2023-48886?
CVE-2023-48886 is associated with CWE ID 502.