← Back

CVE-2022-24969

nvd nist
Published: Jun 9, 2022Modified: Jun 17, 2026

JSON object

Loading...
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD

Description

bypass CVE-2021-25640 > In Apache Dubbo prior to 2.6.12 and 2.7.15, the usage of parseURL method will lead to the bypass of the white host check which can cause open redirect or SSRF vulnerability.

Affected (2)

Products: Apache: Dubbo
1 product
Dubbo
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Apache
Before 2.6.12
From 2.7.0 to 2.7.15

References (2)

Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link

Timeline

No history available yet.