Description
Some component in Dubbo will try to print the formated string of the input arguments, which will possibly cause RCE for a maliciously customized bean with special toString method. In the latest version, we fix the toString call in timeout, cache and some other places. Fixed in Apache Dubbo 2.7.13
Published: 2021-09-09
Score: 9.8 Critical
EPSS: 2.7% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2021-2103 Some component in Dubbo will try to print the formated string of the input arguments, which will possibly cause RCE for a maliciously customized bean with special toString method. In the latest version, we fix the toString call in timeout, cache and some other places. Fixed in Apache Dubbo 2.7.13
Github GHSA Github GHSA GHSA-qvm7-23cj-437v Remote Code Execution in Apache Dubbo
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2024-08-04T00:47:43.813Z

Reserved: 2021-07-06T00:00:00.000Z

Link: CVE-2021-36161

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-09-09T08:15:28.667

Modified: 2024-11-21T06:13:13.923

Link: CVE-2021-36161

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses