Unsafe deserialization occurs within a Dubbo application which has HTTP remoting enabled. An attacker may submit a POST request with a Java object in it to completely compromise a Provider instance of Apache Dubbo, if this instance enables HTTP. This issue affected Apache Dubbo 2.7.0 to 2.7.4, 2.6.0 to 2.6.7, and all 2.5.x versions.
PoC: CVE-2019-17564-FastJson-Gadget
Basic code for creating the Alibaba FastJson + Spring gadget chain, as used to exploit Apache Dubbo in CVE-2019-17564 - more information available at https://www.checkmarx.com/blog/apache-dubbo-unauthenticated-remote-code-execution-vulnerability
PoC: CVE-2019-17564
CVE-2019-17564:Apache Dubbo反序列化漏洞
PoC: CVE-2019-17564
CVE-2019-17564 Apache Dubbo deserialization RCE
PoC: CVE-2019-17564
CVE-2019-17564 : Apache Dubbo Deserialization Remote Code Execution
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Get alerted for CVEs like this
Register your stack and get notified within minutes when a matching CVE drops.
Start monitoring free