Showing 1 vulnerability on this page for org.apache.dubbo:dubbo-rpc-http-invoker

Signals CISA KEV Ransomware Nuclei
Maven vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Deserialization of Untrusted Data in Apache Dubbo

Unsafe deserialization occurs within a Dubbo application which has HTTP remoting enabled. An attacker may submit a POST request with a Java object in it to completely compromise a Provider instance of Apache Dubbo, if this instance enables HTTP. This issue affected Apache Dubbo 2.7.0 to 2.7.4, 2.6.0 to 2.6.7, and all 2.5.x versions.

CWE-502Apr 1, 20201 related artifact
CVSS9.8v3.1EPSS36.5%PoCs6SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX