GHSA-c459-2m73-67hj
SOFA Hessian Remote Command Execution (RCE) Vulnerability
Quick fix
GHSA-c459-2m73-67hj — com.alipay.sofa:hessian: upgrade to the fixed version with the command below.
# pom.xml: bump <version>3.5.5</version> for com.alipay.sofa:hessianDetails
### Impact SOFA Hessian protocol uses a blacklist mechanism to restrict deserialization of potentially dangerous classes for security protection. But there is a gadget chain that can bypass the SOFA Hessian blacklist protection mechanism, and this gadget chain only relies on JDK and does not rely on any third-party components.
### Patches Fixed this issue by update blacklist, users can upgrade to sofahessian version 3.5.5 to avoid this issue.
### Workarounds You can maintain a blacklist yourself in this directory `external/serialize.blacklist`.
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 3.5.5# pom.xml: bump <version>3.5.5</version> for com.alipay.sofa:hessian