ff4j framework 远程代码执行漏洞

2022-12-10 ff4j framework PoC No

Description

FF4J 中某接口存在任意类实例化漏洞。在存在特定依赖的情况下,攻击者可构造恶意请求造成远程代码执行。官方已于 https://github.com/ff4j/ff4j/pull/625 中修复该漏洞。

PoC

None yet. Search at https://trap.biu.life/?ref=rss

References

Related Vulnerabilities