Apache Seata
cpe:2.3:a:apache:seata:*:*:*:*:*:*:*
- >= 2.0.0, < 2.3.0
A deserialization of untrusted data vulnerability has been identified in Apache Seata (incubating) versions 2.0.0 prior to 2.3.0. This vulnerability allows for potential exploitation through improper handling of serialized data, which could be manipulated to achieve unintended effects. Users are advised to upgrade to version 2.3.0, which addresses this issue.
Exploitation of this vulnerability could lead to arbitrary code execution on the server where Apache Seata is running.
Users should upgrade to Apache Seata version 2.3.0 or later, where this vulnerability has been fixed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.