9.8
CVSSv3

CVE-2023-29234

Published: 15/12/2023 Updated: 21/12/2023
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

A deserialization vulnerability existed when decode a malicious package.This issue affects Apache Dubbo: from 3.1.0 up to and including 3.1.10, from 3.2.0 up to and including 3.2.4. Users are recommended to upgrade to the latest version, which fixes the issue.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache dubbo

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> oss-sec mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> CVE-2023-29234: Bypass serialize checks in Apache Dubbo <!--X-Subject-Header-End--> <!--X-Head-of-Message--> From: Albumen K ...