Critical severity9.8NVD Advisory· Published Jun 24, 2021· Updated Jun 17, 2026
CVE-2021-31649
CVE-2021-31649
Description
In applications using jfinal 4.9.08 and below, there is a deserialization vulnerability when using redis,may be vulnerable to remote code execute
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
com.jfinal:jfinalMaven | <= 4.9.08 | — |
Affected products
3Patches
Vulnerability mechanics
References
5- note.youdao.com/notesharenvdExploitThird Party AdvisoryWEB
- note.youdao.com/ynoteshare1/index.htmlnvdExploitThird Party Advisory
- github.com/advisories/GHSA-h3j8-fr5q-8rfrghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-31649ghsaADVISORY
- github.com/jfinal/jfinal/issues/184ghsaWEB
News mentions
0No linked articles in our index yet.