References https://nvd.nist.gov/vuln/detail/CVE-2023-44313 https://www.cve.org/CVERecord?id=CVE-2023-44313 https://github.com/apache/servicecomb-service-center/releases https://github.com/advisories/GHSA-9xc9-xq7w-vpcr https://avd.aliyun.com/detail?id=AVD-2023-44313 https://zhi.oscs1024.com/41057.html https://it.shanghaitech.edu.cn/2024/0206/c8406a1088087/page.htm https://issues.apache.org/jira/browse/SCB-2818 https://github.com/zan8in/wy876-POC/blob/main/Apache/Apache-ServiceComb%E5%AD%98%E5%9C%A8SSRF%E6%BC%8F%E6%B4%9E(CVE-2023-44313).md https://cn-sec.com/archives/2463058.html
Related VulnerabilitiesPoCapache-livy-logs: Apache Livy - Logs ExposedApache Log4j2 远程代码执行漏洞(CVE-2021-44228)畅捷通 T+ POSSyncService.asmx 接口SQL注入漏洞PoCCVE-2026-41042: Apache Gravitino < 1.2.1 - Unauthenticated Remote Code ExecutionPoCmaven-settings-xml-exposure: Apache Maven settings.xml Credentials - ExposureApache IoTDB 认证绕过与远程代码执行漏洞PoCmonitorr-file-upload: Monitorr Services Configuration - Arbitrary File Upload金和OA /c6/JHSoft.Web.CostControl/Decompose/AjaxForCenterBudgetDecompose.ashx SQL 注入漏洞ServiceNow-AI-Platform /assessment_thanks.do 代码执行漏洞(CVE-2026-6875)PoCCVE-2025-68493: Apache Struts XWork - XML External Entity InjectionPoCCVE-2024-42323: Apache HertzBeat < 1.6.0 - SnakeYAML Deserialization Remote Code ExecutionPoCCVE-2025-54988: Apache Tika - XXE Injection