VendorsApachedubboall versions
Vulnerabilities

Apache Software Foundation Dubbo

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

19CVEs
CVE-2021-30181
Apache Dubbo RCE on customers via Script route poisoning (Nashorn script injection)
Published 2021-05-29 · Modified
9.8EPSS 0.606
CVE-2021-30180
Apache Dubbo RCE on customers via Condition route poisoning (Unsafe YAML unmarshaling)
Published 2021-05-31 · Modified
9.8EPSS 0.604
CVE-2019-17564
Unsafe deserialization occurs within a Dubbo application which has HTTP remoting enabled. An attacker may submit a POST request with a Java object in it to completely compromise a Provider instance of Apache Dubbo, if this instance enables HTTP. This issue affected Apache Dubbo 2.7.0 to 2.7.4, 2.6.0 to 2.6.7, and all 2.5.x versions.
Published 2020-04-01 · Modified
9.8EPSS 0.365
CVE-2021-25641
Dubbo Zookeeper does not check serialization id
Published 2021-05-29 · Modified
9.8EPSS 0.212
CVE-2021-43297
Dubbo Hessian cause RCE when parse error
Published 2022-01-10 · Modified
9.8EPSS 0.170
CVE-2020-1948
This vulnerability can affect all Dubbo users stay on version 2.7.6 or lower. An attacker can send RPC requests with unrecognized service name or method name along with some malicious parameter payloads. When the malicious parameter is deserialized, it will execute some malicious code. More details can be found below.
Published 2020-07-14 · Modified
9.8EPSS 0.164
CVE-2023-29234
Bypass serialize checks in Apache Dubbo
Published 2023-12-15 · Modified
9.8EPSS 0.074
CVE-2021-37579
Bypass deserialization checks in Apache Dubbo
Published 2021-09-09 · Modified
9.8EPSS 0.066
CVE-2020-11995
Apache Dubbo default deserialization protocol Hessian2 cause CRE
Published 2021-01-11 · Modified
9.8EPSS 0.057
CVE-2023-23638
Apache Dubbo Deserialization Vulnerability Gadgets Bypass
Published 2023-03-08 · Modified
9.8EPSS 0.048
CVE-2021-30179
Apache Dubbo Pre-auth RCE via Java deserialization in the Generic filter
Published 2021-05-31 · Modified
9.8EPSS 0.041
CVE-2021-36163
Unsafe deserialization in providers using the Hessian protocol
Published 2021-09-07 · Modified
9.8EPSS 0.033
CVE-2021-32824
Regular expression Denial of Service in MooTools
Published 2023-01-03 · Modified
9.8EPSS 0.028
CVE-2022-39198
Apache Dubbo Hession Deserialization Vulnerability Gadgets Bypass
Published 2022-10-18 · Modified
9.8EPSS 0.026
CVE-2021-36161
Unprotected input value toString cause RCE
Published 2021-09-09 · Modified
9.8EPSS 0.025
CVE-2023-46279
Apache Dubbo: Bypass deny serialize list check in Apache Dubbo
Published 2023-12-15 · Modified
9.8EPSS 0.017
CVE-2021-36162
Unprotected yaml deserialization cause RCE
Published 2021-09-07 · Modified
8.8EPSS 0.023
CVE-2021-25640
Open Redirect or SSRF vulnerability usage of parseURL
Published 2021-05-31 · Modified
6.1EPSS 0.021
CVE-2022-24969
bypass of CVE-2021-25640
Published 2022-06-06 · Modified
6.1EPSS 0.018