Back to search
CVE-2022-39198
Published: Oct 18, 2022
Modified: May 13, 2025
PUBLISHED
Description
A deserialization vulnerability existed in dubbo hessian-lite 3.2.12 and its earlier versions, which could lead to malicious code execution. This issue affects Apache Dubbo 2.7.x version 2.7.17 and prior versions; Apache Dubbo 3.0.x version 3.0.11 and prior versions; Apache Dubbo 3.1.x version 3.1.0 and prior versions.
| Vendor | Product | Versions |
|---|---|---|
Apache Software Foundation | Apache Dubbo | affected Apache Dubbo 2.7.x - <= 2.7.17affected Apache Dubbo 3.0.x - <= 3.0.11affected Apache Dubbo 3.1.x - <= 3.1.0 |
Weaknesses (CWE)
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now