Alibabacloud's disclosed vulnerabilities concentrate in the Nacos Spring Project, a service-discovery and configuration-management framework widely embedded in cloud-native and microservices architectures. The observed weakness centers on deserialization of untrusted data, a structural risk inherent to frameworks that accept serialized objects from network clients or dynamic configuration sources.
The number and severity of CVEs published that impact products developed by Alibabacloud over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-39106HIGH An issue in Nacos Group Nacos Spring Project v.1.1.1 and before allows a remote attacker to execute arbitrary code via the SnakeYamls Constructor() component. | Aug 21, 2023 | 8.8 | 22 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Alibabacloud.
Media articles that mention a CVE ID that affects a product developed by Alibabacloud — matched by CVE ID, not by vendor name.