Vulnerabilities > Apache > Dubbo > Medium

DATE CVE VULNERABILITY TITLE RISK
2022-06-09 CVE-2022-24969 Server-Side Request Forgery (SSRF) vulnerability in Apache Dubbo
bypass CVE-2021-25640 > In Apache Dubbo prior to 2.6.12 and 2.7.15, the usage of parseURL method will lead to the bypass of the white host check which can cause open redirect or SSRF vulnerability.
network
low complexity
apache CWE-918
6.1
2021-06-01 CVE-2021-25640 Server-Side Request Forgery (SSRF) vulnerability in Apache Dubbo
In Apache Dubbo prior to 2.6.9 and 2.7.9, the usage of parseURL method will lead to the bypass of white host check which can cause open redirect or SSRF vulnerability.
network
low complexity
apache CWE-918
6.1