VYPR

Sofarpc

by Softstack

Source repositories

CVEs (2)

  • CVE-2023-41331CriSep 12, 2023
    risk 0.64cvss 9.8epss 0.01

    SOFARPC is a Java RPC framework. Versions prior to 5.11.0 are vulnerable to remote command execution. Through a carefully crafted payload, an attacker can achieve JNDI injection or system command execution. In the default configuration of the SOFARPC framework, a blacklist is…

  • CVE-2024-23636CriJan 23, 2024
    risk 0.57cvss 9.8epss 0.01

    SOFARPC is a Java RPC framework. SOFARPC defaults to using the SOFA Hessian protocol to deserialize received data, while the SOFA Hessian protocol uses a blacklist mechanism to restrict deserialization of potentially dangerous classes for security protection. But, prior to…