CVE-2019-17564
- Reference to the description:
- Description:
- Unsafe deserialization occurs within a Dubbo application which has HTTP remoting enabled. An attacker may submit a POST request with a Java object in it to completely compromise a Provider instance of Apache Dubbo, if this instance enables HTTP. This issue affected Apache Dubbo 2.7.0 to 2.7.4, 2.6.0 to 2.6.7, and all 2.5.x versions.
- Last updated date:
- 03/30/2021
Reports
ACTIVELY EXPLOITED
- Type:
- exploitation
- Confidence:
- HIGH
- Date of publishing:
- 05/17/2024
- Type:
- exploit
- Confidence:
- HIGH
- Date of publishing:
- 02/13/2020
- Reference url to background
- Type:
- exploit
- Confidence:
- HIGH
- Date of publishing:
- 02/20/2020
- Reference url to background
https://github.com/Dor-Tumarkin/CVE-2019-17564-FastJson-Gadget
- Type:
- exploit
- Confidence:
- HIGH
- Date of publishing:
- 02/24/2020
- Reference url to background
- Type:
- exploit
- Confidence:
- HIGH
- Date of publishing:
- 06/26/2020
- Reference url to background