Dubbo
Vendor:
First CVE: Apr 1, 2020 · Active for 6 years
19
Total CVEs
More Total CVEs than 93% of tracked products
4.8
Avg CVEs / Year
Higher CVE frequency than 87% of tracked products
9.4
Avg CVSS
Higher Avg CVSS than 87% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Dubbo over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 1, 2020
6 years ago
Most Recent CVE
Dec 15, 2023
952 days ago
CVE Severity & Scoring
Dubbo19 CVEs
11%
84%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network19 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low19 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None17 (89.5%)
Unknown0 (0.0%)
Required2 (10.5%)
Privileges Required
Low1 (5.3%)
High0 (0.0%)
None18 (94.7%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (19 CVEs).
19 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-30181CRITICAL Apache Dubbo prior to 2.6.9 and 2.7.9 supports Script routing which will enable a customer to route the request to the right server. These rules are used by the customers when maki | Jun 1, 2021 | 9.8 | 64 | NO | NO |
CVE-2021-30180CRITICAL Apache Dubbo prior to 2.7.9 support Tag routing which will enable a customer to route the request to the right server. These rules are used by the customers when making a request i | Jun 1, 2021 | 9.8 | 64 | NO | NO |
CVE-2019-17564CRITICAL Unsafe deserialization occurs within a Dubbo application which has HTTP remoting enabled. An attacker may submit a POST request with a Java object in it to completely compromise a | Apr 1, 2020 | 9.8 | 63 | NO | YES |
CVE-2021-25641CRITICAL Each Apache Dubbo server will set a serialization id to tell the clients which serialization protocol it is working on. But for Dubbo versions before 2.7.8 or 2.6.9, an attacker ca | Jun 1, 2021 | 9.8 | 39 | NO | NO |
CVE-2021-43297CRITICAL A deserialization vulnerability existed in dubbo hessian-lite 3.2.11 and its earlier versions, which could lead to malicious code execution. Most Dubbo users use Hessian2 as the de | Jan 10, 2022 | 9.8 | 38 | NO | NO |
CVE-2020-1948CRITICAL This vulnerability can affect all Dubbo users stay on version 2.7.6 or lower. An attacker can send RPC requests with unrecognized service name or method name along with some malici | Jul 14, 2020 | 9.8 | 36 | NO | NO |
CVE-2023-29234CRITICAL A deserialization vulnerability existed when decode a malicious package.This issue affects Apache Dubbo: from 3.1.0 through 3.1.10, from 3.2.0 through 3.2.4.
Users are recommended | Dec 15, 2023 | 9.8 | 34 | NO | NO |
CVE-2021-37579CRITICAL The Dubbo Provider will check the incoming request and the corresponding serialization type of this request meet the configuration set by the server. But there's an exception that | Sep 9, 2021 | 9.8 | 34 | NO | NO |
CVE-2023-23638CRITICAL A deserialization vulnerability existed when dubbo generic invoke, which could lead to malicious code execution.
This issue affects Apache Dubbo 2.7.x version 2.7.21 and prior ve | Mar 8, 2023 | 9.8 | 33 | NO | NO |
CVE-2022-39198CRITICAL A deserialization vulnerability existed in dubbo hessian-lite 3.2.12 and its earlier versions, which could lead to malicious code execution. This issue affects Apache Dubbo 2.7.x v | Oct 18, 2022 | 9.8 | 32 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (19 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
5.3% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (19 CVEs).
Media Mentions
Signals from CVEs in this product scope (19 CVEs).
Top CNAs Publishing CVEs For Dubbo
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 3.1.5 | 1 | 9.8 | 1.7% | 0 | 0 |
| 3.1.0 | 1 | 9.8 | 2.4% | 0 | 0 |