CVE-2020-1948 is a critical deserialization vulnerability affecting Apache Dubbo versions 2.7.6 and earlier. An unauthenticated attacker can send specially crafted RPC requests with unrecognized service or method names, containing malicious parameter payloads. Successful exploitation allows for remote code execution with a CVSS score of 9.8 (Critical), indicating high impact on confidentiality, integrity, and availability. While there is no evidence of active exploitation (KEV) or public exploit code (Metasploit, ExploitDB), the vulnerability has garnered significant community discussion, suggesting awareness and potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.5.0, <= 2.5.10CPE matchmatch criteria | cpe:2.3:a:apache:dubbo:*:*:*:*:*:*:*:* | ||
>= 2.6.0, <= 2.6.7CPE matchmatch criteria | cpe:2.3:a:apache:dubbo:*:*:*:*:*:*:*:* | ||
>= 2.7.0, <= 2.7.6CPE matchmatch criteria | cpe:2.3:a:apache:dubbo:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.