Bypass serialize checks in Apache Dubbo
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 7.4%
exploitation probability
7.4%top 6% of all CVEs
observed exploitation
nono source reports it
A deserialization vulnerability existed when decode a malicious package.This issue affects Apache Dubbo: from 3.1.0 through 3.1.10, from 3.2.0 through 3.2.4.
Users are recommended to upgrade to the latest version, which fixes the issue.
Affected products
Apache Software Foundation · Apache Dubbo