The prior fix for CVE-2024-52046 in Apache MINA AbstractIoBuffer was incomplete. The classname allowlist check is applied after static class initializers can execute, leaving the system vulnerable to deserialization attacks. Attackers can exploit this flaw to execute arbitrary code on vulnerable servers.
Remediation
Upgrade Apache MINA to the latest patched releases 2.0.28, 2.1.11, or 2.2.6 to apply the allowlist check before any untrusted code execution. Audit all deployed applications using Apache MINA to ensure they are running supported, patched versions.
TopVuln sends digest emails with high-risk CVE picks across multiple authoritative sources—curated with EPSS and AI. Choose daily per-stream emails and optional weekly or monthly roundups.