CVE-2023-23638 is a deserialization vulnerability in Apache Dubbo's generic invoke functionality. The issue arises from deserialization of untrusted data during generic invocation handling, which can allow attacker-controlled serialized input to be processed unsafely. According to the provided content, affected versions are Apache Dubbo 2.7.x through 2.7.21, 3.0.x through 3.0.13 and prior versions, and 3.1.x through 3.1.5 and prior versions. Successful exploitation can result in malicious code execution.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
Repository is a minimal Apache Dubbo consumer/provider sample project repurposed as a CVE-2023-23638 proof-of-concept. Key components: - DemoProvider.java + spring/generic-type-provider.xml: starts a Dubbo service (HelloService) on port 20880 and registers it in ZooKeeper at zookeeper://127.0.0.1:2181. - DemoConsumer.java + spring/generic-type-consumer.xml: creates a Dubbo GenericService reference and performs a crafted $invoke("sayHello", ...) call. Exploit logic (DemoConsumer.java): - Uses sun.misc.Unsafe to allocate an instance of org.apache.dubbo.common.utils.SerializeClassChecker without running its constructor. - Reflectively overwrites the static/instance field CLASS_DESERIALIZE_ALLOWED_SET to a custom set containing com.sun.rowset.JdbcRowSetImpl (lowercased), effectively weakening/bypassing Dubbo’s deserialization class restrictions. - Crafts a List containing two Maps that represent generic-serialization objects: 1) A map describing a SerializeClassChecker class with an injected INSTANCE pointing to the manipulated checker. 2) A map describing com.sun.rowset.JdbcRowSetImpl with properties dataSourceName=ldap://192.168.100.1:1389/Basic/Command/calc and autoCommit=true. - Sends this list as the argument to the remote sayHello method via generic invocation, aiming to cause the provider side to deserialize/instantiate the gadget and perform the LDAP JNDI lookup. Notes: - README indicates the consumer must be run with -Ddubbo.hessian.allowNonSerializable=true to allow non-Serializable objects in Hessian, and that ZooKeeper must be provided. - The POC demonstrates a JNDI-based exploitation path; README suggests it can be adapted to other deserialization-based exploitation approaches.
This repository is a proof-of-concept (POC) exploit for CVE-2023-23638, a deserialization vulnerability in Apache Dubbo. The exploit demonstrates how to bypass class deserialization restrictions by manipulating the SerializeClassChecker using Java's Unsafe API, allowing the deserialization of com.sun.rowset.JdbcRowSetImpl. This class is configured to perform a JNDI lookup to an attacker-controlled LDAP server (ldap://192.168.100.1:1389/Basic/Command/calc), which can result in remote code execution on the target system. The repository includes both a provider and consumer setup using Spring and Dubbo, with configuration files for Zookeeper-based service discovery. The main exploit logic resides in DemoConsumer.java, which crafts and sends the malicious payload via Dubbo's GenericService. The exploit requires specific VM arguments and a Java 8 environment. The endpoints involved include the LDAP server for JNDI injection and local Zookeeper/Dubbo service ports.
This repository is an operational exploit tool targeting Apache Dubbo CVE-2023-23638, a deserialization vulnerability in the MetadataService of Dubbo 3.x (and 2.x with manual parameters). The exploit is implemented in Java and provides both a GUI (MainFrame.java) and command-line interface for usage. The core logic is in InsertCode.java (for bytecode injection) and ExecuteCmd.java (for command execution and output retrieval). The exploit works by discovering the MetadataService endpoint, injecting a malicious class (evilClass.java) via Java serialization, and then executing arbitrary system commands on the target server. The output of the command is returned to the attacker, either via the GUI or command line. The tool supports single-target, batch, and scan modes, and can handle different output encodings (UTF-8, GBK). The README provides detailed usage instructions and references for further reading. The exploit requires network access to the Dubbo service port (default 20880) and is effective against vulnerable Dubbo deployments with exposed MetadataService endpoints.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.