CVE-2020-1948
Last modified
CVE-2020-1948 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. This vulnerability can affect all Dubbo users stay on version 2.7.6 or lower. An attacker can send RPC requests with unrecognized service name or method name along with some malicious parameter payloads. EPSS estimates a 13.95% chance of exploitation in the next 30 days.
Description
This vulnerability can affect all Dubbo users stay on version 2.7.6 or lower. An attacker can send RPC requests with unrecognized service name or method name along with some malicious parameter payloads. When the malicious parameter is deserialized, it will execute some malicious code. More details can be found below.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Dubbo | >= 2.5.0, <= 2.5.10 |
| Apache | Dubbo | >= 2.6.0, <= 2.6.7 |
| Apache | Dubbo | >= 2.7.0, <= 2.7.6 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-1948?
How severe is CVE-2020-1948?
How do I fix CVE-2020-1948?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-19470An issue has been found in function DCTStream::getChar in PD…5.5
- CVE-2020-19471An issue has been found in function DCTStream::decodeImage i…5.5
- CVE-2020-19472An issue has been found in function DCTStream::readHuffSym i…5.5
- CVE-2020-19473An issue has been found in function DCTStream::decodeImage i…5.5
- CVE-2020-19474An issue has been found in function Gfx::doShowText in PDF2J…5.5
- CVE-2020-19475An issue has been found in function CCITTFaxStream::lookChar…5.5
- CVE-2020-19481An issue was discovered in GPAC before 0.8.0, as demonstrate…5.5
- CVE-2020-19488An issue was discovered in box_code_apple.c:119 in Gpac MP4B…5.5
- CVE-2020-1949Scripts in Sling CMS before 0.16.0 do not property escape th…6.1
- CVE-2020-19490tinyexr 0.9.5 has a integer overflow over-write in tinyexr::…5.5
- CVE-2020-19491There is an invalid memory access bug in cgif.c that leads t…7.8
- CVE-2020-19492There is a floating point exception in ReadImage that leads …7.8
Are you affected by CVE-2020-1948?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
