CVE-2021-36161 Information
Jun 07, 2022
cve
Description
Some component in Dubbo will try to print the formated string of the input arguments which will possibly cause RCE for a maliciously customized bean with special toString method. In the latest version we fix the toString call in timeout cache and some other places. Fixed in Apache Dubbo 2.7.13
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Reference
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
9.8
Share on: