CVE-2020-11995 Information
Jun 07, 2022
cve
Description
A deserialization vulnerability existed in dubbo 2.7.5 and its earlier versions which could lead to malicious code execution. Most Dubbo users use Hessian2 as the default serialization/deserialization protool during Hessian2 deserializing the HashMap object some functions in the classes stored in HasMap will be executed after a series of program calls however those special functions may cause remote command execution. For example the hashCode() function of the EqualsBean class in rome-1.7.0.jar will cause the remotely load malicious classes and execute malicious code by constructing a malicious request. This issue was fixed in Apache Dubbo 2.6.9 and 2.7.8.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Reference
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
9.8
Share on: