{"id":"GHSA-pfwp-8pq4-g7pv","summary":"Incomplete List of Disallowed Inputs in SOFA-Hessian","details":"SOFA-Hessian through 4.0.2 allows remote attackers to execute arbitrary commands via a crafted serialized Hessian object because blacklisting of com.caucho.naming.QName and com.sun.org.apache.xpath.internal.objects.XString is mishandled, related to Resin Gadget.","aliases":["CVE-2019-9212"],"modified":"2024-03-21T16:59:13.340238Z","published":"2019-03-06T17:36:08Z","database_specific":{"cwe_ids":["CWE-184","CWE-502"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2020-06-16T21:49:03Z","nvd_published_at":"2019-02-27T17:29:00Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-9212"},{"type":"WEB","url":"https://github.com/alipay/sofa-hessian/issues/34"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-pfwp-8pq4-g7pv"},{"type":"PACKAGE","url":"https://github.com/alipay/sofa-hessian"}],"affected":[{"package":{"name":"com.alipay.sofa:hessian","ecosystem":"Maven","purl":"pkg:maven/com.alipay.sofa/hessian"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.0.0"},{"fixed":"4.0.2"}]}],"versions":["4.0.0","4.0.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/03/GHSA-pfwp-8pq4-g7pv/GHSA-pfwp-8pq4-g7pv.json"}},{"package":{"name":"com.alipay.sofa:hessian","ecosystem":"Maven","purl":"pkg:maven/com.alipay.sofa/hessian"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.3.6"}]}],"versions":["3.3.0","3.3.1","3.3.2","3.3.3","3.3.4","3.3.5"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/03/GHSA-pfwp-8pq4-g7pv/GHSA-pfwp-8pq4-g7pv.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}