CVE-2021-30181

CWE-94Code Injection4 documents4 sources
Severity
9.8CRITICAL
EPSS
3.9%
top 11.77%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 1
Latest updateMar 18

Description

Apache Dubbo prior to 2.6.9 and 2.7.9 supports Script routing which will enable a customer to route the request to the right server. These rules are used by the customers when making a request in order to find the right endpoint. When parsing these rules, Dubbo customers use ScriptEngine and run the rule provided by the script which by default may enable executing arbitrary code.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages4 packages

NVDapache/dubbo2.5.02.6.10+1
Mavenorg.apache.dubbo:dubbo2.5.02.7.10
CVEListV5apache_software_foundation/apache_dubboApache Dubbo 2.7.x2.7.9+1
Mavencom.alibaba:dubbo2.5.02.6.9

🔴Vulnerability Details

3
GHSA
Code injection in Apache Dubbo2022-03-18
OSV
Code injection in Apache Dubbo2022-03-18
CVEList
Apache Dubbo RCE on customers via Script route poisoning (Nashorn script injection)2021-05-29