ZeroHour

CVE-2024-52046

Unauthenticated RCE in Apache MINA via Insecure Java Deserialization

CVSS 4.0
10.0 critical
EPSS
24%p98
Published
()
Modified
AI analysis

Apache MINA's ObjectSerializationDecoder processes incoming data using Java's native deserialization protocol without the necessary security checks or defenses (CWE-502), and the flaw carries a maximum CVSS 4.0 score of 10.0. An attacker who can send data to a service using this decoder can deliver a specially crafted serialized object that is reconstructed without validation, leading to remote code execution with no privileges, user interaction, or attack prerequisites required. Exploitation is conditional: only applications that call IoBuffer#getObject(), typically when a ProtocolCodecFilter built with ObjectSerializationCodecFactory is added to the filter chain, are affected, and the FtpServer, SSHd, and Vysper sub-projects are explicitly not impacted. All MINA core 2.0.X, 2.1.X, and 2.2.X releases prior to 2.0.27, 2.1.10, and 2.2.4 respectively are affected. No public proof-of-concept or confirmed in-the-wild exploitation is known and the flaw is not in CISA's KEV, but EPSS assigns a 23.9% probability of exploitation within 30 days (98th percentile), indicating elevated risk.

What to do: Upgrade MINA core to 2.0.27, 2.1.10, or 2.2.4 depending on which 2.x line you run. After upgrading, explicitly allow the classes your protocol needs on the ObjectSerializationDecoder using the new accept(ClassNameMatcher), accept(Pattern), or accept(String...) methods, since the default now rejects all incoming classes. Audit your filter chain for ObjectSerializationCodecFactory usage or any IoBuffer#getObject() call to confirm whether you are exposed; FtpServer, SSHd, and Vysper deployments are not affected.

Affected
Apache MINA coreall 2.0.X releases prior to 2.0.27
Apache MINA coreall 2.1.X releases prior to 2.1.10
Apache MINA coreall 2.2.X releases prior to 2.2.4
Estimated exposure
unknown; plausibly hundreds to low thousands of Java applications, since only MINA 2.x deployments that use ObjectSerializationCodecFactory (or otherwise call… — No active-install or internet-exposure counts were provided in the data, so the estimate rests on deployment patterns: MINA is a moderately adopted Java networking library, but only the subset of users running the object-serialization…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The ObjectSerializationDecoder in Apache MINA uses Java’s native deserialization protocol to process incoming serialized data but lacks the necessary security checks and defenses. This vulnerability allows attackers to exploit the deserialization process by sending specially crafted malicious serialized data, potentially leading to remote code execution (RCE) attacks. This issue affects MINA core versions 2.0.X, 2.1.X and 2.2.X, and will be fixed by the releases 2.0.27, 2.1.10 and 2.2.4. It's also important to note that an application using MINA core library will only be affected if the IoBuffer#getObject() method is called, and this specific method is potentially called when adding a ProtocolCodecFilter instance using the ObjectSerializationCodecFactory class in the filter chain. If your application is specifically using those classes, you have to upgrade to the latest version of MINA core library. Upgrading will not be enough: you also need to explicitly allow the classes the decoder will accept in the ObjectSerializationDecoder instance, using one of the three new methods: /** * Accept class names where the supplied ClassNameMatcher matches for * deserialization, unless they are otherwise rejected. * * @param classNameMatcher the matcher to use */ public void accept(ClassNameMatcher classNameMatcher) /** * Accept class names that match the supplied pattern for * deserialization, unless they are otherwise rejected. * * @param pattern standard Java regexp */ public void accept(Pattern pattern) /** * Accept the wildcard specified classes for deserialization, * unless they are otherwise rejected. * * @param patterns Wildcard file name patterns as defined by * {@link org.apache.commons.io.FilenameUtils#wildcardMatch(String, String) FilenameUtils.wildcardMatch} */ public void accept(String... patterns) By default, the decoder will reject *all* classes that will be present in the incoming data. Note: The FtpServer, SSHd and Vysper sub-project are not affected by this issue.

Vendors
apache
Products
mina
Weakness
CWE-502
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news