{"id":"CVE-2024-46983","aliases":[],"url":"https://o3.security/vulnerability/CVE-2024-46983","summary":"SOFA Hessian Remote Command Execution (RCE) Vulnerability","details":"### Impact\nSOFA Hessian protocol uses a blacklist mechanism to restrict deserialization of potentially dangerous classes for security protection. But there is a gadget chain that can bypass the SOFA Hessian blacklist protection mechanism, and this gadget chain only relies on JDK and does not rely on any third-party components.\n\n### Patches\nFixed this issue by update blacklist, users can upgrade to sofahessian version 3.5.5 to avoid this issue.\n\n### Workarounds\nYou can maintain a blacklist yourself in this directory `external/serialize.blacklist`.\n","published":"2024-09-19T14:49:20Z","modified":"2026-09-10T03:50:18.866569731Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"com.alipay.sofa:hessian","fixedVersion":"3.5.5"}],"fix":{"url":"https://github.com/sofastack/sofa-hessian/commit/764ef4b216aee6aeb4b111aec8947a4e8b53bb87","label":"sofastack/sofa-hessian@764ef4b"},"references":[{"type":"WEB","url":"https://github.com/sofastack/sofa-hessian/security/advisories/GHSA-c459-2m73-67hj"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-46983"},{"type":"WEB","url":"https://github.com/sofastack/sofa-hessian/commit/764ef4b216aee6aeb4b111aec8947a4e8b53bb87"},{"type":"PACKAGE","url":"https://github.com/sofastack/sofa-hessian"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-10T03:50:18.866569731Z"}}