pac4j-core Affected by Java Deserialization Vulnerability
CVE-2023-25581

Currently unrated

Key Information:

Vendor

Pac4j

Status
Vendor
CVE Published:
10 October 2024

Badges

πŸ‘Ύ Exploit Exists🟣 EPSS 19%πŸ“° News Worthy

What is CVE-2023-25581?

The pac4j-core module of the pac4j Java framework is affected by a critical Java deserialization vulnerability, identified as CVE-2023-25581. The vulnerability allows for potential remote code execution (RCE) attacks due to a flaw in the deserialization process. Systems running versions before 4.0 of pac4j-core are at risk, as an attacker could exploit the vulnerability by providing an attribute containing a serialized Java object with a special prefix and Base64 encoding. While a fix has been released in version 4.0.0, there are no known workarounds, and users are strongly advised to upgrade to the latest version to mitigate the risk. This vulnerability highlights the importance of secure coding practices and thorough validation of user-controlled data in software development.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

pac4j < 4.0.0

News Articles

pac4j Java Framework Vulnerable to RCE Attacks

A critical security vulnerability has been discovered in the popular Java framework pac4j, affects versions before 4.0.

References

EPSS Score

19% chance of being exploited in the next 30 days.

Timeline

  • πŸ‘Ύ

    Exploit known to exist

  • πŸ“°

    First article discovered by GBHackers

  • Vulnerability published

  • Vulnerability Reserved

.