Deserialization of Untrusted Data in the Java replace-resolve path in Apache Fory fory-core Java SDK before 1.1.0 on Java/JVM platforms allows a remote attacker to bypass class registration, TypeChecker, and DisallowedList checks and invoke classpath-present readResolve/readExternal hooks via crafted Fory serialized data. Users are recommended to upgrade to version 1.1.0 or later, which fixes this issue.
The vulnerability (CWE-502) lies in the replace-resolve operation processing path during data deserialization in Apache Fory Java SDK. An attacker can submit crafted serialized data in Fory format, which bypasses type verification and blocked class lists. As a result, deserialization invokes readResolve or readExternal methods present in the application's classpath, which may lead to arbitrary code execution on the server side.
An attacker can remotely, without authentication, gain full access to data processed by the application (confidentiality) and modify its state or data (integrity). Depending on available classes in the classpath, arbitrary code execution on the server is possible.
Apache Fory must be immediately updated to version 1.1.0 or later, which eliminates the described vulnerability. Details available at https://fory.apache.org/security.
Apache Fory fory-core Java SDK in versions prior to 1.1.0 running on Java/JVM platforms.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NApache Fory
APPApache< 1.1.0
Related vulnerabilities
Apache Fory C++: type confusion w deserializacji umożliwia RCE
Apache Fory C++: Out-of-bounds Read podczas deserializacji struktur z polami integer
Apache Fory C++: type confusion i out-of-bounds w deserializacji
Apache Fury — pominięcie kontroli klas przy deserializacji wyrażeń lambda
Apache Fory: out-of-bounds read przy deserializacji zero-copy