CVE-2023-23638
MEDIUMApache Dubbo < 2.7.21 - Insecure Deserialization
Title source: ruleDescription
A deserialization vulnerability existed when dubbo generic invoke, which could lead to malicious code execution. This issue affects Apache Dubbo 2.7.x version 2.7.21 and prior versions; Apache Dubbo 3.0.x version 3.0.13 and prior versions; Apache Dubbo 3.1.x version 3.1.5 and prior versions.
Exploits (6)
nomisec
WORKING POC
231 stars
by YYHYlh · poc
https://github.com/YYHYlh/Apache-Dubbo-CVE-2023-23638-exp
github
WORKING POC
5 stars
by JAckLosingHeart · javapoc
https://github.com/JAckLosingHeart/CVE-PoC-Collection/tree/main/dubbo-CVE-2023-23638
Scores
CVSS v3
5.0
EPSS
0.6758
EPSS Percentile
98.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
Classification
CWE
CWE-502
Status
published
Affected Products (2)
apache/dubbo
< 2.7.21
org.apache.dubbo/dubbo
< 2.7.22Maven
Timeline
Published
Mar 08, 2023
Tracked Since
Feb 18, 2026