{"id":"CVE-2020-11995","details":"A deserialization vulnerability existed in dubbo 2.7.5 and its earlier versions, which could lead to malicious code execution. Most Dubbo users use Hessian2 as the default serialization/deserialization protool, during Hessian2 deserializing the HashMap object, some functions in the classes stored in HasMap will be executed after a series of program calls, however, those special functions may cause remote command execution. For example, the hashCode() function of the EqualsBean class in rome-1.7.0.jar will cause the remotely load malicious classes and execute malicious code by constructing a malicious request. This issue was fixed in Apache Dubbo 2.6.9 and 2.7.8.","aliases":["GHSA-74mg-6xqx-2vrq"],"modified":"2026-07-08T20:30:15.549333Z","published":"2021-01-11T10:15:13.187Z","references":[{"type":"ADVISORY","url":"https://lists.apache.org/thread.html/r5b2df4ef479209dc4ced457b3d58a887763b60b9354c3dc148b2eb5b%40%3Cdev.dubbo.apache.org%3E"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/apache/dubbo","events":[{"introduced":"31ca18c712de2016795ba59f499f7c254f9281d5"},{"last_affected":"04576ff4ffdd5872e738b4e10e3905fe513109d2"},{"introduced":"22bb9cbcf75cab6445b8706574a986517855b535"},{"last_affected":"5a6a069986f3627f2d50720c50024df31a3dc38a"},{"introduced":"614bcebc01336ee5047a98f96b28915680c0399c"},{"last_affected":"96de4d9edaa15432e1f67b2d62dab8da9bfb96a1"}],"database_specific":{"cpe":"cpe:2.3:a:apache:dubbo:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"2.5.0"},{"last_affected":"2.5.10"},{"introduced":"2.6.0"},{"last_affected":"2.6.8"},{"introduced":"2.7.0"},{"last_affected":"2.7.7"}],"source":"CPE_RANGE"}}],"versions":["dubbo-2.7.7","dubbo-2.6.8","dubbo-2.6.6","dubbo-2.6.1","dubbo-2.6.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-11995.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}