CVE Database
/

CVE-2022-39198

Back to search

CVE-2022-39198

Published: Oct 18, 2022

Modified: May 13, 2025

PUBLISHED

Description

A deserialization vulnerability existed in dubbo hessian-lite 3.2.12 and its earlier versions, which could lead to malicious code execution. This issue affects Apache Dubbo 2.7.x version 2.7.17 and prior versions; Apache Dubbo 3.0.x version 3.0.11 and prior versions; Apache Dubbo 3.1.x version 3.1.0 and prior versions.

VendorProductVersions

Apache Software Foundation

Apache Dubbo

affected
Apache Dubbo 2.7.x - <= 2.7.17
affected
Apache Dubbo 3.0.x - <= 3.0.11
affected
Apache Dubbo 3.1.x - <= 3.1.0

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now