CVE-2024-52046
Unauthenticated RCE in Apache MINA via Insecure Java Deserialization
Apache MINA's ObjectSerializationDecoder processes incoming data using Java's native deserialization protocol without the necessary security checks or defenses (CWE-502), and the flaw carries a maximum CVSS 4.0 score of 10.0. An attacker who can send data to a service using this decoder can deliver a specially crafted serialized object that is reconstructed without validation, leading to remote code execution with no privileges, user interaction, or attack prerequisites required. Exploitation is conditional: only applications that call IoBuffer#getObject(), typically when a ProtocolCodecFilter built with ObjectSerializationCodecFactory is added to the filter chain, are affected, and the FtpServer, SSHd, and Vysper sub-projects are explicitly not impacted. All MINA core 2.0.X, 2.1.X, and 2.2.X releases prior to 2.0.27, 2.1.10, and 2.2.4 respectively are affected. No public proof-of-concept or confirmed in-the-wild exploitation is known and the flaw is not in CISA's KEV, but EPSS assigns a 23.9% probability of exploitation within 30 days (98th percentile), indicating elevated risk.
What to do: Upgrade MINA core to 2.0.27, 2.1.10, or 2.2.4 depending on which 2.x line you run. After upgrading, explicitly allow the classes your protocol needs on the ObjectSerializationDecoder using the new accept(ClassNameMatcher), accept(Pattern), or accept(String...) methods, since the default now rejects all incoming classes. Audit your filter chain for ObjectSerializationCodecFactory usage or any IoBuffer#getObject() call to confirm whether you are exposed; FtpServer, SSHd, and Vysper deployments are not affected.
| Apache MINA core | all 2.0.X releases prior to 2.0.27 |
| Apache MINA core | all 2.1.X releases prior to 2.1.10 |
| Apache MINA core | all 2.2.X releases prior to 2.2.4 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The ObjectSerializationDecoder in Apache MINA uses Java’s native deserialization protocol to process incoming serialized data but lacks the necessary security checks and defenses. This vulnerability allows attackers to exploit the deserialization process by sending specially crafted malicious serialized data, potentially leading to remote code execution (RCE) attacks. This issue affects MINA core versions 2.0.X, 2.1.X and 2.2.X, and will be fixed by the releases 2.0.27, 2.1.10 and 2.2.4. It's also important to note that an application using MINA core library will only be affected if the IoBuffer#getObject() method is called, and this specific method is potentially called when adding a ProtocolCodecFilter instance using the ObjectSerializationCodecFactory class in the filter chain. If your application is specifically using those classes, you have to upgrade to the latest version of MINA core library. Upgrading will not be enough: you also need to explicitly allow the classes the decoder will accept in the ObjectSerializationDecoder instance, using one of the three new methods: /** * Accept class names where the supplied ClassNameMatcher matches for * deserialization, unless they are otherwise rejected. * * @param classNameMatcher the matcher to use */ public void accept(ClassNameMatcher classNameMatcher) /** * Accept class names that match the supplied pattern for * deserialization, unless they are otherwise rejected. * * @param pattern standard Java regexp */ public void accept(Pattern pattern) /** * Accept the wildcard specified classes for deserialization, * unless they are otherwise rejected. * * @param patterns Wildcard file name patterns as defined by * {@link org.apache.commons.io.FilenameUtils#wildcardMatch(String, String) FilenameUtils.wildcardMatch} */ public void accept(String... patterns) By default, the decoder will reject *all* classes that will be present in the incoming data. Note: The FtpServer, SSHd and Vysper sub-project are not affected by this issue.
- Vendors
- apache
- Products
- mina
- Weakness
- CWE-502
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X