CVE-2020-1948

Description

This vulnerability can affect all Dubbo users stay on version 2.7.6 or lower. An attacker can send RPC requests with unrecognized service name or method name along with some malicious parameter payloads. When the malicious parameter is deserialized, it will execute some malicious code. More details can be found below.

Risk Information

Base Score
9.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
63.597

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2020-1948 are fixed in Apache-dubbo-common 2.7.7Windows
Vulnerabilities CVE-2020-1948 are fixed in Apache-dubbo 2.7.7Windows
Vulnerabilities CVE-2020-1948 are fixed in Apache-dubbo-common for Linux 2.7.7Linux
Vulnerabilities CVE-2020-1948 are fixed in Apache-dubbo for Linux 2.7.7Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234