CVE-2019-17564

Severity CVSS v4.0:
Pending analysis
Type:
CWE-502 Deserialization of Untrusted Dat
Publication date:
01/04/2020
Last modified:
30/03/2021

Description

Unsafe deserialization occurs within a Dubbo application which has HTTP remoting enabled. An attacker may submit a POST request with a Java object in it to completely compromise a Provider instance of Apache Dubbo, if this instance enables HTTP. This issue affected Apache Dubbo 2.7.0 to 2.7.4, 2.6.0 to 2.6.7, and all 2.5.x versions.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:dubbo:*:*:*:*:*:*:*:* 2.5.0 (including) 2.5.10 (including)
cpe:2.3:a:apache:dubbo:*:*:*:*:*:*:*:* 2.6.0 (including) 2.6.7 (including)
cpe:2.3:a:apache:dubbo:*:*:*:*:*:*:*:* 2.7.0 (including) 2.7.4 (including)