GHSA-q897-9jxf-jg9r

    Dashboard / Vulnerabilities / GHSA-q897-9jxf-jg9r

    GHSA-q897-9jxf-jg9r

    Published: 10 Sept 2021Last Modified: 8 Nov 2023

    Summary: Security check skip in Apache Dubbo

    Details: The Dubbo Provider will check the incoming request and the corresponding serialization type of this request meet the configuration set by the server. But there's an exception that the attacker can use to skip the security check (when enabled) and reaching a deserialization operation with native java serialization. Apache Dubbo 2.7.13, 3.0.2 fixed this issue by quickly fail when any unrecognized request was found.

    Affected packages

    Package

    Name: org.apache.dubbo:dubbo

    Purl: pkg:maven/org.apache.dubbo/dubbo

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -2.7.13

    Affected versions

    2.7.0
    2.7.1
    2.7.10
    2.7.11
    2.7.12
    2.7.2
    2.7.3
    2.7.4
    2.7.4.1
    2.7.5
    2.7.6
    2.7.7
    2.7.8
    2.7.9

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-q897-9jxf-jg9r | CVE-DB