{
  "affected": [
    {
      "ranges": [
        {
          "database_specific": {
            "cpe": "cpe:2.3:a:apache:dubbo:*:*:*:*:*:*:*:*",
            "extracted_events": [
              {
                "introduced": "3.1.0"
              },
              {
                "last_affected": "3.1.10"
              },
              {
                "introduced": "3.2.0"
              },
              {
                "last_affected": "3.2.4"
              }
            ],
            "source": "CPE_RANGE"
          },
          "events": [
            {
              "introduced": "db4007e44527451ceda23aa109b4123949b4210e"
            },
            {
              "last_affected": "cbb69a3fdfe66db6c8972d77b5239ba8decb0c9f"
            },
            {
              "introduced": "5cbd95b5d915e9ccad286532873a2b2d09510982"
            },
            {
              "last_affected": "aa63f26ab9c5ee4dd5d7543f3d42dec4034974c8"
            }
          ],
          "repo": "https://github.com/apache/dubbo",
          "type": "GIT"
        }
      ]
    }
  ],
  "database_specific": {
    "cna_assigner": "apache",
    "cwe_ids": [
      "CWE-502"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/29xxx/CVE-2023-29234.json",
    "unresolved_ranges": [
      {
        "extracted_events": [
          {
            "introduced": "3.1.0"
          },
          {
            "last_affected": "3.1.10"
          },
          {
            "introduced": "3.2.0"
          },
          {
            "last_affected": "3.2.4"
          }
        ],
        "source": "AFFECTED_FIELD"
      },
      {
        "extracted_events": [
          {
            "introduced": "3.1.0"
          },
          {
            "fixed": "3.1.10"
          },
          {
            "introduced": "3.2.0"
          },
          {
            "fixed": "3.2.4"
          }
        ],
        "source": "DESCRIPTION"
      }
    ]
  },
  "details": "A deserialization vulnerability existed when decode a malicious package.This issue affects Apache Dubbo: from 3.1.0 through 3.1.10, from 3.2.0 through 3.2.4.\n\nUsers are recommended to upgrade to the latest version, which fixes the issue.",
  "id": "CVE-2023-29234",
  "modified": "2026-08-12T03:51:12.805269246Z",
  "published": "2023-12-15T08:14:47.561Z",
  "references": [
    {
      "type": "WEB",
      "url": "http://www.openwall.com/lists/oss-security/2023/12/15/2"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/29xxx/CVE-2023-29234.json"
    },
    {
      "type": "ADVISORY",
      "url": "https://lists.apache.org/thread/wb2df2whkdnbgp54nnqn0m94rllx8f77"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29234"
    }
  ],
  "schema_version": "1.9.0",
  "summary": "Bypass serialize checks in Apache Dubbo"
}