Uploaded image for project: 'CXF'
  1. CXF
  2. CXF-6711

Aegis Databinding Deserialization Vulnerability

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Closed
    • Major
    • Resolution: Fixed
    • 3.1.4
    • 3.1.5, 3.0.8
    • Aegis Databinding
    • None
    • Unknown

    Description

      Just had a quick look after the topic came up on -users. Aegis Databiding seems to perform unsafe deserialization when serializedWhenUnknown=true. Now sure how common that is (and actually no experience with aegis at all), but if used and enabled that's pretty much direct remote code execution.

      Attachments

        Activity

          People

            dkulp Daniel Kulp
            mbechler Moritz Bechler
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: