com.alibaba:dubbo
Maven5 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting com.alibaba:dubbopage 1 of 1
- CVE-2021-25640MEDIUMCVSS 6.1EG 6.1✓ Fixed in 2.6.92021-06-01
vulnerable: 2.5.0 ... 2.6.8 (20 versions)
In Apache Dubbo prior to 2.6.9 and 2.7.9, the usage of parseURL method will lead to the bypass of white host check which can cause open redirect or SSRF vulnerability.
- CVE-2021-25641CRITICALCVSS 9.8EG 9.8✓ Fixed in 2.6.92021-06-01
vulnerable: 2.5.0 ... 2.6.8 (20 versions)
Each Apache Dubbo server will set a serialization id to tell the clients which serialization protocol it is working on. But for Dubbo versions before 2.7.8 or 2.6.9, an attacker can choose which serialization id the Provider will use by ta…
- CVE-2021-30179CRITICALCVSS 9.8EG 9.8✓ Fixed in 2.6.92021-06-01
vulnerable: 2.5.0 ... 2.6.8 (20 versions)
Apache Dubbo prior to 2.6.9 and 2.7.9 by default supports generic calls to arbitrary methods exposed by provider interfaces. These invocations are handled by the GenericFilter which will find the service and method specified in the first a…
- CVE-2021-30181CRITICALCVSS 9.8EG 9.8✓ Fixed in 2.6.92021-06-01
vulnerable: 2.5.0 ... 2.6.8 (20 versions)
Apache Dubbo prior to 2.6.9 and 2.7.9 supports Script routing which will enable a customer to route the request to the right server. These rules are used by the customers when making a request in order to find the right endpoint. When pars…
- CVE-2022-24969MEDIUMCVSS 6.1EG 6.1✓ Fixed in 2.6.122022-06-09
vulnerable: 2.5.0 ... 2.6.9 (24 versions)
bypass CVE-2021-25640 > In Apache Dubbo prior to 2.6.12 and 2.7.15, the usage of parseURL method will lead to the bypass of the white host check which can cause open redirect or SSRF vulnerability.
Check whether com.alibaba:dubbo is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for com.alibaba:dubbo CVEs against the assets you own.
Start Free Scan →