y_project RuoYi Whitelist Component Deserialization Vulnerability

Vulnerability

A critical deserialization vulnerability has been identified in the y_project RuoYi application, affecting versions through 4.8.0. The issue arises in the Whitelist component's getBeanName function, allowing remote exploitation.

Impact

Exploitation of this vulnerability leads to arbitrary code execution on the server where the application is running.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
6.1
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.