CVE-2021-36163
Severity CVSS v4.0:
Pending analysis
Type:
CWE-502
Deserialization of Untrusted Dat
Publication date:
07/09/2021
Last modified:
14/09/2021
Description
In Apache Dubbo, users may choose to use the Hessian protocol. The Hessian protocol is implemented on top of HTTP and passes the body of a POST request directly to a HessianSkeleton: New HessianSkeleton are created without any configuration of the serialization factory and therefore without applying the dubbo properties for applying allowed or blocked type lists. In addition, the generic service is always exposed and therefore attackers do not need to figure out a valid service/method name pair. This is fixed in 2.7.13, 2.6.10.1
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Base Score 2.0
7.50
Severity 2.0
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:apache:dubbo:*:*:*:*:*:*:*:* | 2.7.0 (including) | 2.7.12 (including) |
cpe:2.3:a:apache:dubbo:*:*:*:*:*:*:*:* | 3.0.0 (including) | 3.0.1 (including) |
To consult the complete list of CPE names with products and versions, see this page