CVE Vulnerabilities

CVE-2021-30181

Published: Jun 01, 2021 | Modified: Jun 10, 2021
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Apache Dubbo prior to 2.6.9 and 2.7.9 supports Script routing which will enable a customer to route the request to the right server. These rules are used by the customers when making a request in order to find the right endpoint. When parsing these rules, Dubbo customers use ScriptEngine and run the rule provided by the script which by default may enable executing arbitrary code.

Affected Software

Name Vendor Start Version End Version
Dubbo Apache 2.5.0 (including) 2.6.10 (excluding)
Dubbo Apache 2.7.0 (including) 2.7.10 (excluding)

References