Vulnerability CVE-2023-29234


Published: 2023-12-15

Description:
A deserialization vulnerability existed when decode a malicious package.This issue affects Apache Dubbo: from 3.1.0 through 3.1.10, from 3.2.0 through 3.2.4.

Users are recommended to upgrade to the latest version, which fixes the issue.

Type:

CWE-502

(Deserialization of Untrusted Data)

 References:
https://lists.apache.org/thread/wb2df2whkdnbgp54nnqn0m94rllx8f77
http://www.openwall.com/lists/oss-security/2023/12/15/2

Copyright 2026, cxsecurity.com

 

Back to Top