Vulnerabilities
Vulnerable Software
Apache:  >> Dubbo  >> 2.7.9  Security Vulnerabilities
Apache Dubbo prior to 2.7.9 support Tag routing which will enable a customer to route the request to the right server. These rules are used by the customers when making a request in order to find the right endpoint. When parsing these YAML rules, Dubbo customers may enable calling arbitrary constructors.
CVSS Score
9.8
EPSS Score
0.032
Published
2021-06-01
Apache Dubbo prior to 2.6.9 and 2.7.9 supports Script routing which will enable a customer to route the request to the right server. These rules are used by the customers when making a request in order to find the right endpoint. When parsing these rules, Dubbo customers use ScriptEngine and run the rule provided by the script which by default may enable executing arbitrary code.
CVSS Score
9.8
EPSS Score
0.033
Published
2021-06-01


Contact Us

Shodan ® - All rights reserved