CVE-2024-47552: Apache Seata Vulnerable to Deserialization of Untrusted Data
Deserialization of Untrusted Data vulnerability in Apache Seata (incubating).
This issue affects Apache Seata (incubating): from 2.0.0 before 2.2.0.
Users are recommended to upgrade to version 2.2.0, which fixes the issue.
References
- github.com/advisories/GHSA-2r4x-667f-mpfh
- github.com/apache/incubator-seata
- github.com/apache/incubator-seata/commit/c0d2ac540b5579e909ae3240f112575313fcad34
- github.com/apache/incubator-seata/releases/tag/v2.2.0
- lists.apache.org/thread/652o82vzk9qrtgksk55cfgpbvdgtkch0
- nvd.nist.gov/vuln/detail/CVE-2024-47552
Detect and mitigate CVE-2024-47552 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →