Some component in Dubbo will try to print the formated string of the input arguments, which will possibly cause RCE for a maliciously customized bean with special toString method. In the latest version, we fix the toString call in timeout, cache and some other places. Fixed in Apache Dubbo 2.7.13
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published: 2021-09-09T07:45:11

Updated: 2024-08-04T00:47:43.813Z

Reserved: 2021-07-06T00:00:00

Link: CVE-2021-36161

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2021-09-09T08:15:28.667

Modified: 2021-09-17T15:47:23.503

Link: CVE-2021-36161

cve-icon Redhat

No data.