CVE-2019-17564: Critical severity apache dubbo vulnerability
Unsafe deserialization occurs within a Dubbo application which has HTTP remoting enabled. An attacker may submit a POST request with a Java object in it to completely compromise a Provider instance of Apache Dubbo, if this instance enables HTTP. This issue affected Apache Dubbo 2.7.0 to 2.7.4, 2.6.0 to 2.6.7, and all 2.5.x versions.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-17564?
CVE-2019-17564 is a vulnerability that allows for unsafe deserialization in a Dubbo application with HTTP remoting enabled.
How does CVE-2019-17564 work?
An attacker can submit a POST request with a Java object to compromise a Provider instance of Apache Dubbo if it has HTTP enabled.
What versions of Apache Dubbo are affected by CVE-2019-17564?
Versions 2.5.0 to 2.5.10, 2.6.0 to 2.6.7, and 2.7.0 to 2.7.4 of Apache Dubbo are affected.
How severe is CVE-2019-17564?
CVE-2019-17564 has a severity level of 9.8 (critical).
How can I fix CVE-2019-17564?
To fix CVE-2019-17564, update Apache Dubbo to a version that is not affected by the vulnerability.