CVE-2021-38241

CRITICAL

Ruoyi <4.6.1 - Code Injection

Title source: llm

Description

Deserialization issue discovered in Ruoyi before 4.6.1 allows remote attackers to run arbitrary code via weak cipher in Shiro framework.

Scores

CVSS v3 9.8
EPSS 0.0089
EPSS Percentile 75.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-502
Status published

Affected Products (1)

ruoyi/ruoyi < 4.6.1

Timeline

Published Dec 16, 2022
Tracked Since Feb 18, 2026