Vulnerability Details CVE-2023-39106
An issue in Nacos Group Nacos Spring Project v.1.1.1 and before allows a remote attacker to execute arbitrary code via the SnakeYamls Constructor() component.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.017
EPSS Ranking 81.7%
CVSS Severity
CVSS v3 Score 8.8
Products affected by CVE-2023-39106
-
cpe:2.3:a:alibabacloud:nacos_spring_project:*