← Back

CVE-2021-36161

nvd nist
Published: Sep 9, 2021Modified: Jun 17, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

Some component in Dubbo will try to print the formated string of the input arguments, which will possibly cause RCE for a maliciously customized bean with special toString method. In the latest version, we fix the toString call in timeout, cache and some other places. Fixed in Apache Dubbo 2.7.13

Affected (1)

Products: Apache: Dubbo
1 product
Dubbo
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
From 2.7.0 to 2.7.13

Timeline

No history available yet.