PT-2020-9918 · Apache · Apache Dubbo

Dor Tumarkin

·

Published

2020-02-10

·

Updated

2025-08-15

·

CVE-2019-17564

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache Dubbo versions 2.5.x Apache Dubbo versions 2.6.0 through 2.6.7 Apache Dubbo versions 2.7.0 through 2.7.4
Description Unsafe deserialization occurs within a Dubbo application which has HTTP remoting enabled. An attacker may submit a POST request with a Java object in it to completely compromise a Provider instance of Apache Dubbo, if this instance enables HTTP.
Recommendations For Apache Dubbo versions 2.5.x, consider disabling HTTP remoting to prevent exploitation until a patch is available. For Apache Dubbo versions 2.6.0 through 2.6.7, consider disabling HTTP remoting to prevent exploitation until a patch is available. For Apache Dubbo versions 2.7.0 through 2.7.4, consider disabling HTTP remoting to prevent exploitation until a patch is available. As a temporary workaround, consider restricting access to the HTTP endpoint to minimize the risk of exploitation.

Exploit

Fix

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

BDU:2025-09902
CVE-2019-17564
GHSA-69WP-3PM3-HXGG

Affected Products

Apache Dubbo