Apache.Dubbo.CVE-2021-25641.Remote.Code.Execution

description-logoDescription

This indicates an attack attempt to exploit a Remote Code Execution Vulnerability in Apache Software Foundation Dubbo.
A remote attacker can exploit this vulnerability by sending a malformed stream containing a malicious object to the exposed service. Successful exploitation can result in arbitrary code execution under the security context of the affected Consumer.

affected-products-logoAffected Products

Apache Software Foundation Dubbo 2.5.0 to 2.6.9
Apache Software Foundation Dubbo 2.7.0 to 2.7.8

Impact logoImpact

System Compromise: Remote attackers can gain control of vulnerable systems.

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)

Version Updates

Date Version Detail
2021-07-15 18.121 Default_action:pass:drop
2021-07-07 18.115
2021-07-07 18.114
2021-07-07 18.113