CVE-2023-44312 MEDIUM

CVE-2023-44312: Apache ServiceComb Service-Center: attacker can query all environment variables of the service-center server

Vendor Apache Software Foundation
Product Apache ServiceComb Service-Center
Weakness CWE-200 · Info exposure
Published January 31, 2024
Last update May 30, 2025

CVSS base score

5.8/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N

What the vulnerability does

01Description

Exposure of Sensitive Information to an Unauthorized Actor in Apache ServiceComb Service-Center.This issue affects Apache ServiceComb Service-Center before 2.1.0 (include). Users are recommended to upgrade to version 2.2.0, which fixes the issue.

Key dates

02Disclosure timeline

January 31, 2024 CVE published
May 30, 2025 Record updated

Related vulnerabilities

04Related CVE