Apache Seata
cpe:2.3:a:apache:seata:*:*:*:*:*:*:*
- >= 2.0.0, < 2.2.0
A deserialization of untrusted data vulnerability has been identified in Apache Seata (incubating) versions 2.0.0 prior to 2.2.0. This vulnerability occurs in jraft mode on the Apache Seata Server.
Exploitation of this vulnerability could lead to deserialization issues, potentially allowing for arbitrary code execution or other malicious actions, depending on the context in which Seata is used.
Users are advised to upgrade to Apache Seata version 2.2.0 or later, which addresses this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.