restlet / restlet-framework-java

The first REST API framework for Java
https://restlet.talend.com
649 stars 284 forks source link

About the RCE 0day Vulnerability #1394

Open chenhliang opened 2 years ago

chenhliang commented 2 years ago

Component of restlet-framework-java [spring-beans 3.2.8.RELEASE]. The RCE 0day vulnerability may exist. Please check whether exists. If yes, how to rectify the fault. Thank you.

Tembrel commented 2 years ago

Restlet does not refer to Spring's SerializationUtils, which appears to be at the heart of the vulnerability.