CVE-2023-40571

weblogic-framework is a tool for detecting weblogic vulnerabilities. Versions 0.2.3 and prior do not verify the returned data packets, and there is a deserialization vulnerability which may lead to remote code execution. When weblogic-framework gets the command echo, it directly deserializes the data returned by the server without verifying it. At the same time, the classloader loads a lot of deserialization calls. In this case, the malicious serialized data returned by the server will cause remote code execution. Version 0.2.4 contains a patch for this issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:weblogic-framework_project:weblogic-framework:*:*:*:*:*:*:*:*

History

21 Nov 2024, 08:19

Type Values Removed Values Added
Summary
  • (es) weblogic-framework es una herramienta para detectar vulnerabilidades de weblogic. Las versiones 0.2.3 y anteriores no verifican los paquetes de datos devueltos, y existe una vulnerabilidad de deserialización que puede conducir a la ejecución remota de código. Cuando weblogic-framework recibe el comando echo, deserializa directamente los datos devueltos por el servidor sin verificarlos. Al mismo tiempo, el cargador de clases carga muchas llamadas de deserialización. En este caso, los datos serializados maliciosos devueltos por el servidor provocarán la ejecución remota de código. La versión 0.2.4 contiene un parche para este problema.
References () https://github.com/dream0x01/weblogic-framework/releases/tag/v0.2.4 - Release Notes () https://github.com/dream0x01/weblogic-framework/releases/tag/v0.2.4 - Release Notes
References () https://github.com/dream0x01/weblogic-framework/security/advisories/GHSA-hjwj-4f3q-44h3 - Vendor Advisory () https://github.com/dream0x01/weblogic-framework/security/advisories/GHSA-hjwj-4f3q-44h3 - Vendor Advisory

01 Sep 2023, 13:11

Type Values Removed Values Added
References (MISC) https://github.com/dream0x01/weblogic-framework/releases/tag/v0.2.4 - (MISC) https://github.com/dream0x01/weblogic-framework/releases/tag/v0.2.4 - Release Notes
References (MISC) https://github.com/dream0x01/weblogic-framework/security/advisories/GHSA-hjwj-4f3q-44h3 - (MISC) https://github.com/dream0x01/weblogic-framework/security/advisories/GHSA-hjwj-4f3q-44h3 - Vendor Advisory
CPE cpe:2.3:a:weblogic-framework_project:weblogic-framework:*:*:*:*:*:*:*:*
First Time Weblogic-framework Project weblogic-framework
Weblogic-framework Project
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

25 Aug 2023, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-08-25 21:15

Updated : 2024-11-21 08:19


NVD link : CVE-2023-40571

Mitre link : CVE-2023-40571

CVE.ORG link : CVE-2023-40571


JSON object : View

Products Affected

weblogic-framework_project

  • weblogic-framework
CWE
CWE-502

Deserialization of Untrusted Data