CVE-2024-56180

CVE-2024-56180: Apache EventMesh: raft Hessian Deserialization Vulnerability allowing remote code execution

Vendor Apache Software Foundation
Product Apache EventMesh
Weakness CWE-502 · Unsafe deserialization
Published February 14, 2025
Last update February 18, 2025

CVSS base score

What the vulnerability does

Description

CWE-502 Deserialization of Untrusted Data at the eventmesh-meta-raft plugin module in Apache EventMesh master branch without release version on windows\linux\mac os e.g. platforms allows attackers to send controlled message and remote code execute via hessian deserialization rpc protocol. Users can use the code under the master branch in project repo or version 1.11.0 to fix this issue.

Key dates

Disclosure timeline

February 14, 2025 CVE published
February 18, 2025 Record updated