Deserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.
{ "nvd_published_at": "2023-01-31T16:15:00Z", "github_reviewed_at": "2023-02-08T22:32:36Z", "severity": "CRITICAL", "github_reviewed": true, "cwe_ids": [ "CWE-502" ] }