CVE-2019-9212

Source
https://nvd.nist.gov/vuln/detail/CVE-2019-9212
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-9212.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2019-9212
Aliases
Withdrawn
2019-06-28T18:49:33Z
Published
2019-02-27T17:29:00Z
Modified
2024-10-03T23:47:21.254055Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

SOFA-Hessian through 4.0.2 allows remote attackers to execute arbitrary commands via a crafted serialized Hessian object because blacklisting of com.caucho.naming.QName and com.sun.org.apache.xpath.internal.objects.XString is mishandled, related to Resin Gadget. NOTE: The vendor doesn’t consider this issue a vulnerability because the blacklist is being misused. SOFA Hessian supports custom blacklist and a disclaimer was posted encouraging users to update the blacklist or to use the whitelist feature for their specific needs since the blacklist is not being actively updated

References

Affected packages

Git / github.com/sofastack/sofa-hessian

Affected ranges

Type
GIT
Repo
https://github.com/sofastack/sofa-hessian
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected

Affected versions

v3.*

v3.3.0
v3.3.1
v3.3.2
v3.3.3

v4.*

v4.0.0
v4.0.1
v4.0.2