CVE-2023-46279

CRITICAL

Apache Dubbo <3.1.5 - Use After Free

Title source: llm
STIX 2.1

Description

Deserialization of Untrusted Data vulnerability in Apache Dubbo.This issue only affects Apache Dubbo 3.1.5. Users are recommended to upgrade to the latest version, which fixes the issue.

References (2)

Core 2
Core References
Mailing List, Vendor Advisory vendor-advisory
https://lists.apache.org/thread/zw53nxrkrfswmk9n3sfwxmcj7x030nmo

Scores

CVSS v3 9.8
EPSS 0.0149
EPSS Percentile 81.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-502
Status published
Products (2)
apache/dubbo 3.1.5
org.apache.dubbo/dubbo 3.1.5 - 3.1.6Maven
Published Dec 15, 2023
Tracked Since Feb 18, 2026