9.8
CVSSv3

CVE-2023-46279

Published: 15/12/2023 Updated: 19/12/2023
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

Deserialization of Untrusted Data vulnerability in Apache Dubbo.This issue only affects Apache Dubbo 3.1.5. Users are recommended to upgrade to the latest version, which fixes the issue.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache dubbo 3.1.5

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> oss-sec mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> CVE-2023-46279: Apache Dubbo: Bypass deny serialize list check in Apache Dubbo <!--X-Subject-Header-End--> <!--X-Head-of-Messa ...