https://seclists.org/oss-sec/2023/q4/279: CVE-2023-46279: Apache Dubbo: Bypass deny serialize list check in Apache Dubbo
Published Dec 15, 2023
·Updated
Affected Software
1 affected component
Apache Dubbo
Frequently Asked Questions
1
What is the severity of CVE-2023-46279?
CVE-2023-46279 has a severity rating of important.
2
Which versions of Apache Dubbo are affected by CVE-2023-46279?
Apache Dubbo version 3.1.5 is the only affected version for CVE-2023-46279.
3
What is the nature of the vulnerability described in CVE-2023-46279?
CVE-2023-46279 is a deserialization of untrusted data vulnerability that allows bypassing deny serialize list checks.
4
How do I fix CVE-2023-46279?
To fix CVE-2023-46279, users should upgrade to the latest version of Apache Dubbo.
5
When was CVE-2023-46279 published?
CVE-2023-46279 was published on December 15, 2023.