Unprotected input value toString cause RCE
3Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackepss 2.5%
probabilidad de explotación
2.5%top 16% de las CVE
explotación observada
noninguna fuente lo reporta
Some component in Dubbo will try to print the formated string of the input arguments, which will possibly cause RCE for a maliciously customized bean with special toString method. In the latest version, we fix the toString call in timeout, cache and some other places. Fixed in Apache Dubbo 2.7.13
Productos afectados
Apache Software Foundation · Apache Dubbo