SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-37579

But there's an exception that the attacker can use to skip the security check (when enabled) and reaching a deserialization operation with native java serialization.

CRITICAL 9.8EPSS 6.56%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (6.56%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

The Dubbo Provider will check the incoming request and the corresponding serialization type of this request meet the configuration set by the server. But there's an exception that the attacker can use to skip the security check (when enabled) and reaching a deserialization operation with native java serialization. Apache Dubbo 2.7.13, 3.0.2 fixed this issue by quickly fail when any unrecognized request was found.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
6.56% probability · 93th percentile
CISA KEV
Not listed
Weakness
CWE-502
Affected
apache/dubbo
Source
security@apache.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.