Loading
Unsafe deserialization occurs within a Dubbo application which has HTTP remoting enabled. An attacker may submit a POST request with a Java object in it to completely compromise a Provider instance of Apache Dubbo, if this instance enables HTTP. This issue affected Apache Dubbo 2.7.0 to 2.7.4, 2.6.0 to 2.6.7, and all 2.5.x versions.
Use CWE-502, Apache vendor hub and Dubbo product page to widen CVE-2019-17564 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2023-46279, CVE-2023-29234 and CVE-2021-32824 for nearby disclosures in the same product family.