Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vp5x-3v8r-qprw

Опубликовано: 12 янв. 2022
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

Deserialization of Untrusted Data in Dubbo

A deserialization vulnerability existed in dubbo hessian-lite 3.2.11 and its earlier versions, which could lead to malicious code execution. Most Dubbo users use Hessian2 as the default serialization/deserialization protocol, during Hessian catch unexpected exceptions, Hessian will log out some imformation for users, which may cause remote command execution. This issue affects Apache Dubbo Apache Dubbo 2.6.x versions prior to 2.6.12; Apache Dubbo 2.7.x versions prior to 2.7.15; Apache Dubbo 3.0.x versions prior to 3.0.5.

Пакеты

Наименование

org.apache.dubbo:dubbo

maven
Затронутые версииВерсия исправления

>= 2.6.0, < 2.6.12

2.6.12

Наименование

org.apache.dubbo:dubbo

maven
Затронутые версииВерсия исправления

>= 2.7.0, < 2.7.15

2.7.15

Наименование

org.apache.dubbo:dubbo

maven
Затронутые версииВерсия исправления

>= 3.0.0, < 3.0.5

3.0.5

EPSS

Процентиль: 97%
0.42301
Средний

9.8 Critical

CVSS3

Дефекты

CWE-502

Связанные уязвимости

CVSS3: 9.8
nvd
около 4 лет назад

A deserialization vulnerability existed in dubbo hessian-lite 3.2.11 and its earlier versions, which could lead to malicious code execution. Most Dubbo users use Hessian2 as the default serialization/deserialization protocol, during Hessian catch unexpected exceptions, Hessian will log out some imformation for users, which may cause remote command execution. This issue affects Apache Dubbo Apache Dubbo 2.6.x versions prior to 2.6.12; Apache Dubbo 2.7.x versions prior to 2.7.15; Apache Dubbo 3.0.x versions prior to 3.0.5.

EPSS

Процентиль: 97%
0.42301
Средний

9.8 Critical

CVSS3

Дефекты

CWE-502