Maven package
org.apache.seata/seata-core
pkg:maven/org.apache.seata/seata-core
Vulnerabilities (1)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2024-22399 | Cri | 9.8 | >= 2.0.0, < 2.1.0 | 2.1.0 | Sep 16, 2024 | Deserialization of Untrusted Data vulnerability in Apache Seata. When developers disable authentication on the Seata-Server and do not use the Seata client SDK dependencies, they may construct uncontrolled serialized malicious requests by directly sending bytecode based on the |
- affected >= 2.0.0, < 2.1.0fixed 2.1.0
Deserialization of Untrusted Data vulnerability in Apache Seata. When developers disable authentication on the Seata-Server and do not use the Seata client SDK dependencies, they may construct uncontrolled serialized malicious requests by directly sending bytecode based on the