CVE-2024-47552
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Mar 20, 2025
Updated: Apr 1, 2025
CWE ID 502
Summary
CVE-2024-47552 is a Deserialization of Untrusted Data vulnerability identified in Apache Seata (incubating). This issue puts versions 2.0.0 through 2.1.9 of the software at risk. Attackers can exploit this vulnerability by sending malicious data to be deserialized, potentially leading to arbitrary code execution. To mitigate this risk, it is strongly advised that users upgrade to Apache Seata (incubating) version 2.2.0, which contains the necessary fixes.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- Apache Corporation