Логотип exploitDog
bind:CVE-2021-43297
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-43297

Количество 2

Количество 2

nvd логотип

CVE-2021-43297

около 4 лет назад

A deserialization vulnerability existed in dubbo hessian-lite 3.2.11 and its earlier versions, which could lead to malicious code execution. Most Dubbo users use Hessian2 as the default serialization/deserialization protocol, during Hessian catch unexpected exceptions, Hessian will log out some imformation for users, which may cause remote command execution. This issue affects Apache Dubbo Apache Dubbo 2.6.x versions prior to 2.6.12; Apache Dubbo 2.7.x versions prior to 2.7.15; Apache Dubbo 3.0.x versions prior to 3.0.5.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-vp5x-3v8r-qprw

около 4 лет назад

Deserialization of Untrusted Data in Dubbo

CVSS3: 9.8
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-43297

A deserialization vulnerability existed in dubbo hessian-lite 3.2.11 and its earlier versions, which could lead to malicious code execution. Most Dubbo users use Hessian2 as the default serialization/deserialization protocol, during Hessian catch unexpected exceptions, Hessian will log out some imformation for users, which may cause remote command execution. This issue affects Apache Dubbo Apache Dubbo 2.6.x versions prior to 2.6.12; Apache Dubbo 2.7.x versions prior to 2.7.15; Apache Dubbo 3.0.x versions prior to 3.0.5.

CVSS3: 9.8
46%
Средний
около 4 лет назад
github логотип
GHSA-vp5x-3v8r-qprw

Deserialization of Untrusted Data in Dubbo

CVSS3: 9.8
46%
Средний
около 4 лет назад

Уязвимостей на страницу