CVE-2021-25641
Dubbo Zookeeper does not check serialization id
Vexday Risk Score
8Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS —EPSS 17.7%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
29 may 2021Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
Each Apache Dubbo server will set a serialization id to tell the clients which serialization protocol it is working on. But for Dubbo versions before 2.7.8 or 2.6.9, an attacker can choose which serialization id the Provider will use by tampering with the byte preamble flags, aka, not following the server's instruction. This means that if a weak deserializer such as the Kryo and FST are somehow in code scope (e.g. if Kryo is somehow a part of a dependency), a remote unauthenticated attacker can tell the Provider to use the weak deserializer, and then proceed to exploit it.
Productos afectados
Apache Software Foundation · Apache Dubbo¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →