Security Advisory

CVE-2023-29234

9.8
CRITICAL

Vulnerability Description

A deserialization vulnerability existed when decode a malicious package.This issue affects Apache Dubbo: from 3.1.0 through 3.1.10, from 3.2.0 through 3.2.4. Users are recommended to upgrade to the latest version, which fixes the issue.
Published Date December 15, 2023
Official Source NIST NVD Advisory