PT-2024-13189 · Apache · Apache Servicecomb Service-Center

Published

2024-01-31

·

Updated

2024-06-28

·

CVE-2023-44312

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache ServiceComb Service-Center versions prior to 2.1.0 Apache ServiceComb Service-Center versions prior to 2.2.0 is not needed as 2.1.0 is already included in the prior to 2.1.0 statement.
Description The issue is related to the exposure of sensitive information to an unauthorized actor in Apache ServiceComb Service-Center. Users are recommended to upgrade to version 2.2.0 to fix the issue.
Recommendations For Apache ServiceComb Service-Center versions prior to 2.1.0, upgrade to version 2.2.0 to resolve the issue.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-44312
GHSA-R8XP-52MQ-RMM8
GO-2024-2496

Affected Products

Apache Servicecomb Service-Center