CVE-2021-30180

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
01/06/2021
Last modified:
10/06/2021

Description

Apache Dubbo prior to 2.7.9 support Tag routing which will enable a customer to route the request to the right server. These rules are used by the customers when making a request in order to find the right endpoint. When parsing these YAML rules, Dubbo customers may enable calling arbitrary constructors.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:dubbo:*:*:*:*:*:*:*:* 2.7.0 (including) 2.7.10 (excluding)