CVE-2023-24162: Dromara Hutool Deserialization of Untrusted Data vulnerability
9.8
CVSS Score
3.1
Basic Information
CVE ID
GHSA ID
EPSS Score
0.36542%
CWE
Published
1/31/2023
Updated
2/16/2023
KEV Status
No
Technology
Java
Technical Details
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| cn.hutool:hutool-all | maven | <= 5.8.11 |
Vulnerability Intelligence
Miggo AI
Root Cause Analysis
The vulnerability documentation explicitly identifies XmlUtil.readObjectFromXml as the entry point. The Gitee issue shows this method directly passes user-controlled XML to XMLDecoder.readObject(), which is known to be unsafe. Multiple authoritative sources (CVE, GHSA, and project's own issue tracker) confirm this function's role in the exploit chain. The maintainer's response about adding warnings but not fixing the method further confirms its vulnerable nature.