First published: Fri Dec 15 2023(Updated: )
Deserialization of Untrusted Data vulnerability in Apache Dubbo.This issue only affects Apache Dubbo 3.1.5. Users are recommended to upgrade to the latest version, which fixes the issue.
Credit: security@apache.org security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Dubbo | =3.1.5 | |
maven/org.apache.dubbo:dubbo | =3.1.5 | 3.1.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-46279 is a serious vulnerability that can lead to remote code execution due to deserialization of untrusted data.
To fix CVE-2023-46279, you should upgrade your Apache Dubbo version from 3.1.5 to 3.1.6 or later.
Only Apache Dubbo version 3.1.5 is affected by CVE-2023-46279.
CVE-2023-46279 is a deserialization of untrusted data vulnerability.
Yes, a patch is available in Apache Dubbo version 3.1.6 which resolves CVE-2023-46279.