CVE Database
/

CVE-2020-1948

Back to search

CVE-2020-1948

Published: Jul 14, 2020

Modified: Aug 4, 2024

PUBLISHED

Description

This vulnerability can affect all Dubbo users stay on version 2.7.6 or lower. An attacker can send RPC requests with unrecognized service name or method name along with some malicious parameter payloads. When the malicious parameter is deserialized, it will execute some malicious code. More details can be found below.

VendorProductVersions

n/a

Apache Dubbo

affected
Apache Dubbo 2.5.x, 2.6.0 to 2.6.8, 2.7.0 to 2.7.7

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now