VDB
Sign up
CRITICAL9.8

GHSA-c459-2m73-67hj

SOFA Hessian Remote Command Execution (RCE) Vulnerability

Quick fix

GHSA-c459-2m73-67hj — com.alipay.sofa:hessian: upgrade to the fixed version with the command below.

# pom.xml: bump <version>3.5.5</version> for com.alipay.sofa:hessian

Details

### Impact SOFA Hessian protocol uses a blacklist mechanism to restrict deserialization of potentially dangerous classes for security protection. But there is a gadget chain that can bypass the SOFA Hessian blacklist protection mechanism, and this gadget chain only relies on JDK and does not rely on any third-party components.

### Patches Fixed this issue by update blacklist, users can upgrade to sofahessian version 3.5.5 to avoid this issue.

### Workarounds You can maintain a blacklist yourself in this directory `external/serialize.blacklist`.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/com.alipay.sofa:hessian
Introduced in: 0Fixed in: 3.5.5
Fix# pom.xml: bump <version>3.5.5</version> for com.alipay.sofa:hessian

References