Description
Deserialization of Untrusted Data vulnerability in Apache Dubbo.This issue only affects Apache Dubbo 3.1.5. Users are recommended to upgrade to the latest version, which fixes the issue.
Remediation
References
http://www.openwall.com/lists/oss-security/2023/12/15/3
https://lists.apache.org/thread/zw53nxrkrfswmk9n3sfwxmcj7x030nmo
Related Vulnerabilities
CVE-2023-3223 Vulnerability in maven package io.undertow:undertow-servlet
CVE-2021-23342 Vulnerability in npm package docsify
CVE-2022-41966 Vulnerability in maven package com.thoughtworks.xstream:xstream
CVE-2022-31160 Vulnerability in maven package org.webjars.npm:jquery-ui
CVE-2023-32070 Vulnerability in maven package org.xwiki.rendering:xwiki-rendering-syntax-html5