CVE-2025-15222

⚪ Do wiadomości

Deserializacja w Dromara Sa-Token umożliwia zdalne wykonanie ataku.

CVSS
5.0
EPSS
0.3%
Exploit
none
Vendor
Opis źródłowy (NVD)

A vulnerability has been found in Dromara Sa-Token up to 1.44.0. This issue affects the function ObjectInputStream.readObject of the file SaSerializerTemplateForJdkUseBase64.java. Such manipulation leads to deserialization. The attack can be executed remotely. This attack is characterized by high complexity. The exploitability is assessed as difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

deserialization Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS5.0
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.3%
Opublikowano (NVD)2025-12-30 06:15:40 UTC
Ostatnia modyfikacja (NVD)2026-10-05 17:10:00 UTC
Referencje