
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2024-56180 is a deserialization vulnerability (CWE-502) discovered in the eventmesh-meta-raft plugin module of Apache EventMesh master branch. The vulnerability affects multiple platforms including Windows, Linux, and macOS, and was disclosed on February 14, 2025. The vulnerability exists in unreleased versions of the master branch, allowing attackers to execute remote code through hessian deserialization RPC protocol (OSS Security).
The vulnerability is classified as CWE-502 (Deserialization of Untrusted Data) and affects the eventmesh-meta-raft plugin module. The issue specifically involves the hessian deserialization RPC protocol, which can be exploited by sending controlled messages to trigger remote code execution (NVD).
The vulnerability allows attackers to execute remote code on affected systems through controlled message delivery, potentially compromising the security of the affected Apache EventMesh installations (OSS Security).
Users are advised to either update to version 1.11.0 or use the code from the master branch in the project repository, both of which contain fixes for this vulnerability (OSS Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."