GHSA-p694-23q3-rvrc
CRITICALCVE-2017-15708In Apache Synapse, by default no authentication is required for Java Remote Method Invocation (RMI). So Apache Synapse 3.0.1 or all previous releases (3.0.0, 2.1.0, 2.0.0, 1.2, 1.1.2, 1.1.1) allows remote code execution attacks that can be performed by injecting specially crafted serialized objects. And the presence of Apache Commons Collections 3.2.1 (commons-collections-3.2.1.jar) or previous ve
- Affected
- < 3.0.1
- Fixed in
- 3.0.1
- Weakness
- CWE-74
- Published
- 2020-11-04
- Source
- github
GHSANVDMITREreferencereferencereferencereferencereferencereference