VYPR
Critical severity9.8NVD Advisory· Published Sep 16, 2024· Updated Jun 17, 2026

CVE-2024-22399

CVE-2024-22399

Description

Deserialization of Untrusted Data vulnerability in Apache Seata.

When developers disable authentication on the Seata-Server and do not use the Seata client SDK dependencies, they may construct uncontrolled serialized malicious requests by directly sending bytecode based on the Seata private protocol.

This issue affects Apache Seata: 2.0.0, from 1.0.0 through 1.8.0.

Users are recommended to upgrade to version 2.1.0/1.8.1, which fixes the issue.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.apache.seata:seata-coreMaven
>= 2.0.0, < 2.1.02.1.0
org.apache.seata:seata-coreMaven
>= 1.0.0, < 1.8.11.8.1

Affected products

4
  • Apache/Seata2 versions
    cpe:2.3:a:apache:seata:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:apache:seata:*:*:*:*:*:*:*:*range: >=1.0.0,<1.8.1
    • cpe:2.3:a:apache:seata:2.0.0:*:*:*:*:*:*:*
  • ghsa-coords
    Range: >= 2.0.0, < 2.1.0
  • Apache Software Foundation/Apache Seatav5
    Range: 2.0.0

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.