Vulnerability Description
This vulnerability can affect all Dubbo users stay on version 2.7.6 or lower. An attacker can send RPC requests with unrecognized service name or method name along with some malicious parameter payloads. When the malicious parameter is deserialized, it will execute some malicious code. More details can be found below.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Dubbo | >= 2.5.0, <= 2.5.10 |
Related Weaknesses (CWE)
References
- https://lists.apache.org/thread.html/rbaa41711b3e7a8cd20e9013737423ddd079ddc12f9Broken Link
- https://nsfocusglobal.com/apache-dubbo-remote-code-execution-vulnerability-cve-2Third Party Advisory
- https://lists.apache.org/thread.html/rbaa41711b3e7a8cd20e9013737423ddd079ddc12f9Broken Link
FAQ
What is CVE-2020-1948?
CVE-2020-1948 is a vulnerability with a CVSS score of 9.8 (CRITICAL). This vulnerability can affect all Dubbo users stay on version 2.7.6 or lower. An attacker can send RPC requests with unrecognized service name or method name along with some malicious parameter payloa...
How severe is CVE-2020-1948?
CVE-2020-1948 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-1948?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Dubbo.