Vulnerability Details CVE-2023-29234
A deserialization vulnerability existed when decode a malicious package.This issue affects Apache Dubbo: from 3.1.0 through 3.1.10, from 3.2.0 through 3.2.4.
Users are recommended to upgrade to the latest version, which fixes the issue.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.876
EPSS Ranking 99.4%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2023-29234
-
cpe:2.3:a:apache:dubbo:3.1.0
-
cpe:2.3:a:apache:dubbo:3.1.1
-
cpe:2.3:a:apache:dubbo:3.1.2
-
cpe:2.3:a:apache:dubbo:3.1.3
-
cpe:2.3:a:apache:dubbo:3.1.4
-
cpe:2.3:a:apache:dubbo:3.1.5
-
cpe:2.3:a:apache:dubbo:3.2.0