CVE Database
/

CVE-2021-36163

Back to search

CVE-2021-36163

Published: Sep 7, 2021

Modified: Aug 4, 2024

PUBLISHED

Description

In Apache Dubbo, users may choose to use the Hessian protocol. The Hessian protocol is implemented on top of HTTP and passes the body of a POST request directly to a HessianSkeleton: New HessianSkeleton are created without any configuration of the serialization factory and therefore without applying the dubbo properties for applying allowed or blocked type lists. In addition, the generic service is always exposed and therefore attackers do not need to figure out a valid service/method name pair. This is fixed in 2.7.13, 2.6.10.1

VendorProductVersions

Apache Software Foundation

Apache Dubbo

affected
Apache Dubbo 2.7.x - <= 2.7.12
affected
Apache Dubbo 2.6.x - <= 2.6.10

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now