CVE-2023-46279

CRITICAL9.8EPSS 1.5%

Apache Dubbo: Bypass deny serialize list check in Apache Dubbo

發布日:2023/12/15修改日:2025/2/13

描述

Deserialization of Untrusted Data vulnerability in Apache Dubbo.This issue only affects Apache Dubbo 3.1.5. Users are recommended to upgrade to the latest version, which fixes the issue.

受影響套件(1)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1CRITICAL9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

參考連結(4)