CVE-2019-17564 describes an unsafe deserialization vulnerability in Apache Dubbo versions 2.7.0 to 2.7.4, 2.6.0 to 2.6.7, and all 2.5.x versions, specifically when HTTP remoting is enabled. This critical vulnerability (CVSS 9.8) allows an unauthenticated attacker to completely compromise a Dubbo Provider instance by submitting a crafted POST request containing a malicious Java object. While not on the CISA KEV list, its high EPSS score (0.94) and the existence of Nuclei templates indicate a high likelihood of exploitation. Community discussion and GitHub references confirm the availability of exploit code, despite no Metasploit or ExploitDB entries.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.5.0, <= 2.5.10CPE matchmatch criteria | cpe:2.3:a:apache:dubbo:*:*:*:*:*:*:*:* | ||
>= 2.6.0, <= 2.6.7CPE matchmatch criteria | cpe:2.3:a:apache:dubbo:*:*:*:*:*:*:*:* | ||
>= 2.7.0, <= 2.7.4CPE matchmatch criteria | cpe:2.3:a:apache:dubbo:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.