Vulnerabilities > Apache > Dubbo > 2.6.7

DATE CVE VULNERABILITY TITLE RISK
2023-01-03 CVE-2021-32824 Deserialization of Untrusted Data vulnerability in Apache Dubbo
Apache Dubbo is a java based, open source RPC framework.
network
low complexity
apache CWE-502
critical
9.8
2022-06-09 CVE-2022-24969 Server-Side Request Forgery (SSRF) vulnerability in Apache Dubbo
bypass CVE-2021-25640 > In Apache Dubbo prior to 2.6.12 and 2.7.15, the usage of parseURL method will lead to the bypass of the white host check which can cause open redirect or SSRF vulnerability.
network
apache CWE-918
5.8
2022-01-10 CVE-2021-43297 Deserialization of Untrusted Data vulnerability in Apache Dubbo
A deserialization vulnerability existed in dubbo hessian-lite 3.2.11 and its earlier versions, which could lead to malicious code execution.
network
low complexity
apache CWE-502
7.5
2021-06-01 CVE-2021-25640 Server-Side Request Forgery (SSRF) vulnerability in Apache Dubbo
In Apache Dubbo prior to 2.6.9 and 2.7.9, the usage of parseURL method will lead to the bypass of white host check which can cause open redirect or SSRF vulnerability.
network
low complexity
apache CWE-918
6.1
2021-06-01 CVE-2021-25641 Deserialization of Untrusted Data vulnerability in Apache Dubbo
Each Apache Dubbo server will set a serialization id to tell the clients which serialization protocol it is working on.
network
low complexity
apache CWE-502
7.5
2021-06-01 CVE-2021-30179 Deserialization of Untrusted Data vulnerability in Apache Dubbo
Apache Dubbo prior to 2.6.9 and 2.7.9 by default supports generic calls to arbitrary methods exposed by provider interfaces.
network
low complexity
apache CWE-502
critical
9.8
2021-06-01 CVE-2021-30181 Unspecified vulnerability in Apache Dubbo
Apache Dubbo prior to 2.6.9 and 2.7.9 supports Script routing which will enable a customer to route the request to the right server.
network
low complexity
apache
7.5
2021-01-11 CVE-2020-11995 Deserialization of Untrusted Data vulnerability in Apache Dubbo
A deserialization vulnerability existed in dubbo 2.7.5 and its earlier versions, which could lead to malicious code execution.
network
low complexity
apache CWE-502
7.5
2020-07-14 CVE-2020-1948 Deserialization of Untrusted Data vulnerability in Apache Dubbo
This vulnerability can affect all Dubbo users stay on version 2.7.6 or lower.
network
low complexity
apache CWE-502
7.5
2020-04-01 CVE-2019-17564 Deserialization of Untrusted Data vulnerability in Apache Dubbo
Unsafe deserialization occurs within a Dubbo application which has HTTP remoting enabled.
network
apache CWE-502
6.8