← Back

CVE-2019-17564

Published: Apr 1, 2020Modified: Jun 17, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

Unsafe deserialization occurs within a Dubbo application which has HTTP remoting enabled. An attacker may submit a POST request with a Java object in it to completely compromise a Provider instance of Apache Dubbo, if this instance enables HTTP. This issue affected Apache Dubbo 2.7.0 to 2.7.4, 2.6.0 to 2.6.7, and all 2.5.x versions.

Affected (3)

Products: Apache: Dubbo
1 product
Dubbo
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Apache
From 2.5.0 to 2.5.10
From 2.6.0 to 2.6.7
From 2.7.0 to 2.7.4

Timeline

No history available yet.