CVE-2023-29234 is a critical deserialization vulnerability affecting Apache Dubbo versions 3.1.0 through 3.1.10 and 3.2.0 through 3.2.4. An unauthenticated attacker can exploit this flaw remotely by sending a malicious package, leading to complete compromise of the affected system. With a CVSS score of 9.8 (CRITICAL) and high EPSS and FAUCET Risk scores, the vulnerability poses a significant threat, allowing for high impact to confidentiality, integrity, and availability. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered substantial community discussion, indicating awareness and potential for future exploitation. Users are strongly advised to upgrade to the latest patched versions immediately.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.1.0, <= 3.1.10CPE matchmatch criteria | cpe:2.3:a:apache:dubbo:*:*:*:*:*:*:*:* | ||
>= 3.2.0, <= 3.2.4CPE matchmatch criteria | cpe:2.3:a:apache:dubbo:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.