Apache Dubbo prior to 2.7.9 support Tag routing which will enable a customer to route the request to the right server. These rules are used by the customers when making a request in order to find the right endpoint. When parsing these YAML rules, Dubbo customers may enable calling arbitrary constructors.
Advisories
Source ID Title
EUVD EUVD EUVD-2022-1367 Apache Dubbo prior to 2.7.9 support Tag routing which will enable a customer to route the request to the right server. These rules are used by the customers when making a request in order to find the right endpoint. When parsing these YAML rules, Dubbo customers may enable calling arbitrary constructors.
Github GHSA Github GHSA GHSA-7wfc-x4f7-gg2x Code injection in Apache Dubbo
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2024-08-03T22:24:59.649Z

Reserved: 2021-04-07T00:00:00

Link: CVE-2021-30180

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-06-01T14:15:09.937

Modified: 2024-11-21T06:03:28.323

Link: CVE-2021-30180

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses