CVE-2023-23638: Apache Dubbo Deserialization Vulnerability Gadgets Bypass
A deserialization vulnerability existed when dubbo generic invoke, which could lead to malicious code execution.
This issue affects Apache Dubbo 2.7.x version 2.7.21 and prior versions; Apache Dubbo 3.0.x version 3.0.13 and prior versions; Apache Dubbo 3.1.x version 3.1.5 and prior versions.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-23638?
CVE-2023-23638 is a deserialization vulnerability that existed when dubbo generic invoke, which could lead to malicious code execution.
Which versions of Apache Dubbo are affected by CVE-2023-23638?
CVE-2023-23638 affects Apache Dubbo 2.7.x version 2.7.21 and prior versions, Apache Dubbo 3.0.x version 3.0.13 and prior versions, and Apache Dubbo 3.1.x version 3.1.5 and prior versions.
What is the severity of CVE-2023-23638?
CVE-2023-23638 has a severity rating of 9.8 (Critical).
How can CVE-2023-23638 be exploited?
CVE-2023-23638 can be exploited through the deserialization of malicious code during dubbo generic invoke.
How can I mitigate CVE-2023-23638?
To mitigate CVE-2023-23638, it is recommended to update to the latest patched version of Apache Dubbo.