Apache Ratis is a highly customizable Raft protocol implementation in Java. Raft is a easily understandable consensus algorithm to manage replicated state. Apache Ratis could be used in any Java application where state should be replicated between multiple instances.
Apache Ratis suffers from an unsafe Java deserialization vulnerability in its RPC error handling. The cause and stack-trace bytes carried in an RPC reply exception are deserialized through IOUtils.readObject with no class filtering, so a malicious server (or a man-in-the-middle) can return a crafted exception whose bytes are deserialized in the receiving client. A gadget chain was run through the real IOUtils.readObject in ratis-3.3.1. This can result in remote code execution against a Ratis client where a suitable gadget is present on the client classpath. The trust precondition is a compromised/malicious server or MITM, so a peer-trust rebuttal is likely.