xxl-rpc v1.7.0 was discovered to contain a deserialization vulnerability via the component com.xxl.rpc.core.remoting.net.impl.netty.codec.NettyDecode#decode
.
{ "severity": "CRITICAL", "github_reviewed_at": "2023-06-09T22:52:46Z", "nvd_published_at": "2023-06-07T21:15:13Z", "cwe_ids": [ "CWE-502" ], "github_reviewed": true }