← All CVEs

CVE-2021-43297

critical · 9.8

A deserialization vulnerability existed in dubbo hessian-lite 3.2.11 and its earlier versions, which could lead to malicious code execution. Most Dubbo users use Hessian2 as the default serialization/deserialization protocol, during Hessian catch unexpected exceptions, Hessian will log out some imformation for users, which may cause remote command execution. This issue affects Apache Dubbo Apache Dubbo 2.6.x versions prior to 2.6.12; Apache Dubbo 2.7.x versions prior to 2.7.15; Apache Dubbo 3.0.x versions prior to 3.0.5.

9.8
CVSS
17.0%
EPSS (exploit prob.)
97th
EPSS percentile
2022-01-10
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-502

Affected products

VendorProductAffected versions
apachedubbo>= 2.6.0, < 2.6.12
apachedubbo>= 2.7.0, < 2.7.15
apachedubbo>= 3.0.0, < 3.0.5

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2021-43297