VYPR

Xxl RPC

by Xxl RPC Project

CVEs (2)

  • CVE-2023-33496CriJun 7, 2023
    risk 0.64cvss 9.8epss 0.01

    xxl-rpc v1.7.0 was discovered to contain a deserialization vulnerability via the component com.xxl.rpc.core.remoting.net.impl.netty.codec.NettyDecode#decode.

  • CVE-2023-45146CriOct 18, 2023
    risk 0.59cvss 9.0epss 0.01

    XXL-RPC is a high performance, distributed RPC framework. With it, a TCP server can be set up using the Netty framework and the Hessian serialization mechanism. When such a configuration is used, attackers may be able to connect to the server and provide malicious serialized…