Description
Deserialization of Untrusted Data vulnerability in Apache Dubbo.This issue only affects Apache Dubbo 3.1.5. Users are recommended to upgrade to the latest version, which fixes the issue.
Remediation
References
http://www.openwall.com/lists/oss-security/2023/12/15/3
https://lists.apache.org/thread/zw53nxrkrfswmk9n3sfwxmcj7x030nmo
Related Vulnerabilities
CVE-2023-29212 Vulnerability in maven package org.xwiki.platform:xwiki-platform-panels-ui
CVE-2021-21366 Vulnerability in npm package xmldom
CVE-2019-1003087 Vulnerability in maven package org.jenkins-ci.plugins:labmanager
CVE-2023-49068 Vulnerability in maven package org.apache.dolphinscheduler:dolphinscheduler-api