First published: Wed Mar 08 2023(Updated: )
A deserialization vulnerability existed when dubbo generic invoke, which could lead to malicious code execution. This issue affects Apache Dubbo 2.7.x version 2.7.21 and prior versions; Apache Dubbo 3.0.x version 3.0.13 and prior versions; Apache Dubbo 3.1.x version 3.1.5 and prior versions.
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Dubbo | >=2.7.0<=2.7.21 | |
Apache Dubbo | >=3.0.0<=3.0.13 | |
Apache Dubbo | >=3.1.0<=3.1.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-23638 is a deserialization vulnerability that existed when dubbo generic invoke, which could lead to malicious code execution.
CVE-2023-23638 affects Apache Dubbo 2.7.x version 2.7.21 and prior versions, Apache Dubbo 3.0.x version 3.0.13 and prior versions, and Apache Dubbo 3.1.x version 3.1.5 and prior versions.
CVE-2023-23638 has a severity rating of 9.8 (Critical).
CVE-2023-23638 can be exploited through the deserialization of malicious code during dubbo generic invoke.
To mitigate CVE-2023-23638, it is recommended to update to the latest patched version of Apache Dubbo.