CVE-2019-17564
CRITICAL 9.8EPSS 36.5%
Unsafe deserialization occurs within a Dubbo application which has HTTP remoting enabled. An attacker may submit a POST request with a Java object in it to completely compromise a Provider instance of Apache Dubbo, if this instance enables HTTP. This issue affected Apache Dubbo 2.7.0 to 2.7.4, 2.6.0 to 2.6.7, and all 2.5.x versions.
- CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v2.0
- 6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P - EPSS
- 36.51% chance of exploitation in the next 30 days, 98th percentile
- Nuclei
- critical · CWE-502
- Published
- 2020-04-01
- Updated
- 2024-08-05
Proof-of-concept exploits (6)
- Dor-Tumarkin/CVE-2019-17564-FastJson-Gadget16★ · 2022-12-10
- Exploit-3389/CVE-2019-175640★ · 2020-02-17
- Hu3sky/CVE-2019-175641★ · 2020-02-14
- Jaky5155/CVE-2019-175642★ · 2020-02-13
- fairyming/CVE-2019-175648★ · 2020-02-24
- r00t4dm/CVE-2019-175640★ · 2020-02-12