MEDIUM
bypass of CVE-2021-25640
Published Jun 6, 2022
6.1
MEDIUMCVSS 3.1
EPSS 1.84%
Description
bypass CVE-2021-25640 > In Apache Dubbo prior to 2.6.12 and 2.7.15, the usage of parseURL method will lead to the bypass of the white host check which can cause open redirect or SSRF vulnerability.
Affected products
-
Affected
- ≥ Apache Dubbo 2.6.x, ≤ 2.6.12
- ≥ Apache Dubbo 2.7.x, < 2.7.15
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Apache Software Foundation | Apache Dubbo | unknown | Affected
|
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (6)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-6051 Advisory
- https://github.com/advisories/GHSA-gm48-83x4-84jg Advisory
- https://github.com/advisories/GHSA-gw4j-4229-q4px
- https://lists.apache.org/thread/1xbckc3467wfk5r7n2o44r2brdsbwxgr x_refsource_MISCBroken Link
- https://nvd.nist.gov/vuln/detail/CVE-2021-25640
- https://nvd.nist.gov/vuln/detail/CVE-2022-24969
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apache
Published Jun 6, 2022
Updated Aug 3, 2024
Reserved Feb 11, 2022
Link CVE-2022-24969
CISA Vulnrichment
No data
Red Hat
No data
GitHub
Link GHSA-GM48-83X4-84JG