SOFA Hessian Remote Command Execution (RCE) Vulnerability
SOFA Hessian protocol uses a denylist mechanism to restrict deserialization of potentially dangerous classes for security protection. But there is a gadget chain that can bypass the SOFA Hessian denylist protection mechanism, and this gadget chain only relies on JDK and does not rely on any third-party components.