Описание
Server-side request forgery in Apache Dubbo
bypass CVE-2021-25640 > In Apache Dubbo prior to 2.6.12 and 2.7.15, the usage of parseURL method will lead to the bypass of the white host check which can cause open redirect or SSRF vulnerability.
Пакеты
Наименование
org.apache.dubbo:dubbo
maven
Затронутые версииВерсия исправления
>= 2.5.0, < 2.7.15
2.7.15
Наименование
com.alibaba:dubbo
maven
Затронутые версииВерсия исправления
>= 2.5.0, < 2.6.12
2.6.12
Связанные уязвимости
CVSS3: 6.1
nvd
больше 3 лет назад
bypass CVE-2021-25640 > In Apache Dubbo prior to 2.6.12 and 2.7.15, the usage of parseURL method will lead to the bypass of the white host check which can cause open redirect or SSRF vulnerability.