CVE-2024-22399 is a Critical deserialization of untrusted data vulnerability affecting Apache Seata versions 1.0.0 through 1.8.0 and 2.0.0. If authentication is disabled and the Seata client SDK is not used, attackers can send malicious bytecode via the private protocol, leading to potential remote code execution. With a CVSS score of 9.8 (CRITICAL), this vulnerability is easily exploitable over the network without user interaction or privileges, allowing for complete compromise of confidentiality, integrity, and availability. While there is no known active exploitation, public exploit code, or Metasploit/Nuclei modules, the high EPSS score and community discussion indicate significant concern, urging immediate upgrade to versions 1.8.1 or 2.1.0.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.0.0, < 1.8.1CPE matchmatch criteria | cpe:2.3:a:apache:seata:*:*:*:*:*:*:*:* | ||
2.0.0CPE matchmatch criteria | cpe:2.3:a:apache:seata:2.0.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.