Critical severity9.8NVD Advisory· Published Jan 31, 2023· Updated Jun 17, 2026
CVE-2023-24162
CVE-2023-24162
Description
Deserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
cn.hutool:hutool-allMaven | <= 5.8.11 | — |
Affected products
3- Dromara/Hutooldescription
Patches
Vulnerability mechanics
References
4- gitee.com/dromara/hutool/issues/I6AEX2nvdExploitThird Party AdvisoryWEB
- github.com/dromara/hutool/issues/2855nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-77h8-5j3h-jcjfghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-24162ghsaADVISORY
News mentions
0No linked articles in our index yet.