CVE-2021-25640
published 2021-06-01CVE-2021-25640: In Apache Dubbo prior to 2.6.9 and 2.7.9, the usage of parseURL method will lead to the bypass of white host check which can cause open redirect or SSRF…
PriorityP427medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
2.07%
79.2th percentile
In Apache Dubbo prior to 2.6.9 and 2.7.9, the usage of parseURL method will lead to the bypass of white host check which can cause open redirect or SSRF vulnerability.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | dubbo | < 2.6.12 | 2.6.12 |
| apache | dubbo | >= 2.5.0 < 2.6.9 | 2.6.9 |
| apache | dubbo | >= 2.7.0 < 2.7.9 | 2.7.9 |
| apache | dubbo | >= 2.7.0 < 2.7.15 | 2.7.15 |
| apache_software_foundation | apache_dubbo | Apache Dubbo 2.6.x – 2.6.12 | — |
| apache_software_foundation | apache_dubbo | >= Apache Dubbo 2.7.x < 2.7.15 | 2.7.15 |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
ghsa6.1MEDIUM
osv6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Server-side request forgery in Apache Dubbo
osv·2022-06-10·CVSS 6.1
CVE-2022-24969 [MEDIUM] Server-side request forgery in Apache Dubbo
Server-side request forgery in Apache Dubbo
bypass CVE-2021-25640 > In Apache Dubbo prior to 2.6.12 and 2.7.15, the usage of parseURL method will lead to the bypass of the white host check which can cause open redirect or SSRF vulnerability.
GHSA
Server-side request forgery in Apache Dubbo
ghsa·2022-06-10·CVSS 6.1
CVE-2022-24969 [MEDIUM] CWE-601 Server-side request forgery in Apache Dubbo
Server-side request forgery in Apache Dubbo
bypass CVE-2021-25640 > In Apache Dubbo prior to 2.6.12 and 2.7.15, the usage of parseURL method will lead to the bypass of the white host check which can cause open redirect or SSRF vulnerability.
OSV
Server-Side Request Forgery in Apache Dubbo
osv·2022-03-18
CVE-2021-25640 [MEDIUM] Server-Side Request Forgery in Apache Dubbo
Server-Side Request Forgery in Apache Dubbo
In Apache Dubbo prior to 2.6.9 and 2.7.10, the usage of parseURL method will lead to the bypass of white host check which can cause open redirect or SSRF vulnerability.
GHSA
Server-Side Request Forgery in Apache Dubbo
ghsa·2022-03-18
CVE-2021-25640 [MEDIUM] CWE-601 Server-Side Request Forgery in Apache Dubbo
Server-Side Request Forgery in Apache Dubbo
In Apache Dubbo prior to 2.6.9 and 2.7.10, the usage of parseURL method will lead to the bypass of white host check which can cause open redirect or SSRF vulnerability.
No detection rules found.
No public exploits indexed.
https://lists.apache.org/thread.html/re4cab8855361a454d2af106fb3dad76259e723015fd7e09cb4f9eb77%40%3Cdev.dubbo.apache.org%3Ehttps://lists.apache.org/thread.html/re4cab8855361a454d2af106fb3dad76259e723015fd7e09cb4f9eb77%40%3Cdev.dubbo.apache.org%3Ehttps://lists.apache.org/thread.html/re4cab8855361a454d2af106fb3dad76259e723015fd7e09cb4f9eb77%40%3Cdev.dubbo.apache.org%3Ehttps://lists.apache.org/thread.html/re4cab8855361a454d2af106fb3dad76259e723015fd7e09cb4f9eb77%40%3Cdev.dubbo.apache.org%3E
2021-06-01
Published