CVE-2024-46983: SOFA Hessian Remote Command Execution (RCE) Vulnerability
(updated )
SOFA Hessian protocol uses a denylist mechanism to restrict deserialization of potentially dangerous classes for security protection. But there is a gadget chain that can bypass the SOFA Hessian denylist protection mechanism, and this gadget chain only relies on JDK and does not rely on any third-party components.
References
Detect and mitigate CVE-2024-46983 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →