CVE-2021-43297
CRITICALApache Dubbo <2.6.12, <2.7.15, <3.0 - Code Injection
Title source: llmDescription
A deserialization vulnerability existed in dubbo hessian-lite 3.2.11 and its earlier versions, which could lead to malicious code execution. Most Dubbo users use Hessian2 as the default serialization/deserialization protocol, during Hessian catch unexpected exceptions, Hessian will log out some imformation for users, which may cause remote command execution. This issue affects Apache Dubbo Apache Dubbo 2.6.x versions prior to 2.6.12; Apache Dubbo 2.7.x versions prior to 2.7.15; Apache Dubbo 3.0.x versions prior to 3.0.5.
Exploits (2)
Scores
CVSS v3
9.8
EPSS
0.4630
EPSS Percentile
97.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-502
Status
published
Affected Products (2)
apache/dubbo
< 2.6.12
org.apache.dubbo/dubbo
< 2.6.12Maven
Timeline
Published
Jan 10, 2022
Tracked Since
Feb 18, 2026