Apache MINA CVE-2024-52046: CVSS 10.0 Flaw Enables RCE via Unsafe Serialization

Teilen:

The Apache Software Foundation (ASF) has released patches to address a maximum severity vulnerability in the MINA Java network application framework that could result in remote code execution under specific conditions.

Tracked as CVE-2024-52046, the vulnerability carries a CVSS score of 10.0. It affects versions 2.0.X, 2.1.X, and 2.2.X.

“The ObjectSerializationDecoder in Apache MINA uses Java’s native deserialization protocol to process incoming serialized data but lacks the necessary security checks and defenses,” the project maintainers said in an advisory released on December 25, 2024.

“This vulnerability allows attackers to exploit the deserialization process by sending specially crafted malicious serialized data, potentially leading to remote code execution (RCE) attacks.”

However, it bears noting that the vulnerability is exploitable only if the “IoBuffer#getObject()” method is invoked in combination with certain classes such as ProtocolCodecFilter and ObjectSerializationCodecFactory.

“Upgrading will not be enough: you also need to explicitly allow the classes the decoder will accept in the ObjectSerializationDecoder instance, using one of the three new methods,” Apache said.

The disclosure comes days after the ASF remediated multiple flaws spanning Tomcat (CVE-2024-56337), Traffic Control (CVE-2024-45387), and HugeGraph-Server (CVE-2024-43441).

Earlier this month, Apache also fixed a critical security flaw in the Struts web application framework (CVE-2024-53677) that an attacker could abuse to obtain remote code execution. Active exploitation attempts have since been detected.

Users of these products are strongly advised to update their installations to the latest versions as soon as possible to safeguard against potential threats.

Quelle

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
12:42 am, Juni 11, 2025
Wetter-Symbol 14°C
L: 13° | H: 15°
broken clouds
Luftfeuchtigkeit: 78 %
Druck: 1021 mb
Wind: 11 mph E
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 67%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:43 am
Sonnenuntergang: 9:16 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
13° | 15°°C 0 mm 0% 12 mph 80 % 1021 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
15° | 25°°C 0 mm 0% 12 mph 73 % 1017 mb 0 mm/h
Fr. Juni 13 10:00 pm
Wetter-Symbol
16° | 28°°C 1 mm 100% 9 mph 89 % 1019 mb 0 mm/h
Sa. Juni 14 10:00 pm
Wetter-Symbol
16° | 25°°C 1 mm 100% 11 mph 98 % 1018 mb 0 mm/h
So. Juni 15 10:00 pm
Wetter-Symbol
14° | 23°°C 0 mm 0% 11 mph 84 % 1023 mb 0 mm/h
Today 1:00 am
Wetter-Symbol
14° | 14°°C 0 mm 0% 5 mph 78 % 1021 mb 0 mm/h
Today 4:00 am
Wetter-Symbol
13° | 14°°C 0 mm 0% 5 mph 80 % 1021 mb 0 mm/h
Today 7:00 am
Wetter-Symbol
15° | 15°°C 0 mm 0% 6 mph 79 % 1021 mb 0 mm/h
Today 10:00 am
Wetter-Symbol
21° | 21°°C 0 mm 0% 7 mph 62 % 1021 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
23° | 23°°C 0 mm 0% 10 mph 48 % 1019 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
23° | 23°°C 0 mm 0% 11 mph 47 % 1019 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
20° | 20°°C 0 mm 0% 12 mph 53 % 1018 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
15° | 15°°C 0 mm 0% 10 mph 65 % 1018 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€96,174.07
-0.24%
Ethereum(ETH)
€2,451.12
4.77%
Fesseln(USDT)
€0.88
-0.03%
XRP(XRP)
€2.02
-0.34%
Solana(SOL)
€144.01
2.69%
USDC(USDC)
€0.88
0.01%
Dogecoin(DOGE)
€0.172920
2.00%
Shiba Inu(SHIB)
€0.000011
1.96%
Pepe(PEPE)
€0.000011
3.77%
Peanut das Eichhörnchen(PNUT)
€0.260305
2.56%
Nach oben scrollen