CVE-2023-23638

CVSS V2 None CVSS V3 None
Description
A deserialization vulnerability existed when dubbo generic invoke, which could lead to malicious code execution. This issue affects Apache Dubbo 2.7.x version 2.7.21 and prior versions; Apache Dubbo 3.0.x version 3.0.13 and prior versions; Apache Dubbo 3.1.x version 3.1.5 and prior versions.
Overview
  • CVE ID
  • CVE-2023-23638
  • Assigner
  • security@apache.org
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2023-03-08T11:15:10
  • Last Modified Date
  • 2023-03-14T17:57:21
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:apache:dubbo:*:*:*:*:*:*:*:* 1 OR 2.7.0 2.7.21
cpe:2.3:a:apache:dubbo:*:*:*:*:*:*:*:* 1 OR 3.0.0 3.0.13
cpe:2.3:a:apache:dubbo:*:*:*:*:*:*:*:* 1 OR 3.1.0 3.1.5
References
Reference URL Reference Tags
https://lists.apache.org/thread/8h6zscfzj482z512d2v5ft63hdhzm0cb Issue Tracking Vendor Advisory
History
Created Old Value New Value Data Type Notes
2023-04-17 06:07:22 Added to TrackCVE
2023-04-17 06:07:26 Weakness Enumeration new