PT-2021-21149 · Apache · Apache Dubbo

Qin Ce

·

Published

2021-09-09

·

Updated

2021-09-17

·

CVE-2021-36161

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache Dubbo versions prior to 2.7.13
Description A potential issue exists where some component in Dubbo attempts to print the formatted string of input arguments. This could lead to remote code execution (RCE) if a maliciously customized bean with a special toString method is used.
Recommendations For versions prior to 2.7.13, update to Apache Dubbo 2.7.13 to resolve the issue.

Fix

Use of Externally-Controlled Format String

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-36161
GHSA-QVM7-23CJ-437V

Affected Products

Apache Dubbo