Apache Dubbo - Unauthenticated Access
Apache Dubbo Unauthenticated Access were detected.
共找到 7 条公开漏洞记录
Apache Dubbo Unauthenticated Access were detected.
A deserialization vulnerability existed when decode a malicious package.This issue affects Apache Dubbo: from 3.1.0 through 3.1.10, from 3.2.0 through 3.2.4. Users are recommended to upgrade to the latest version, which fixes the issue.
Apache Dubbo default admin credentials were discovered.
Dubbo是一个高性能优秀的服务框架。CVE-2021-43297中,在Dubbo Hessian-Lite 3.2.11及之前版本中存在潜在RCE攻击风险。Hessian-Lite在遇到序列化异常时会输出相关信息,这可能导致触发某些恶意定制的Bean的toString方法,从而引发远程代码执行。
Each Apache Dubbo server will set a serialization id to tell the clients which serialization protocol it is working on. But for Dubbo versions before 2.7.8 or 2.6.9, an attacker can choose which serialization id the Provider will use by tampering with the byte preamble flags, aka, not following the server's instruction. This means that if a weak deserializer such as the Kryo and FST are somehow in code scope (e.g. if Kryo is somehow a part of a dependency), a remote unauthenticated attacker can tell the Provider to use the weak deserializer, and then proceed to exploit it.
Apache Dubbo 是美国阿帕奇(Apache)基金会的一款基于 Java 的轻量级 RPC(远程过程调用)框架。该产品提供了基于接口的远程呼叫、容错和负载平衡以及自动服务注册和发现等功能。cluster 是 Dubbo 项目的集群模块。 Apache Dubbo cluster 的受影响版本中的脚本路由模块存在远程代码执行漏洞。 Apache Dubbo cluster 通过脚本路由使客户能够将请求路由到正确的服务器,客户在发出请求以找到正确的端点时使用这些规则。在解析这些规则时,Dubbo 客户使用 ScriptEngine 并运行脚本提供的规则,默认情况下可以执行任意代码。
Unsafe deserialization occurs within a Dubbo application which has HTTP remoting enabled. An attacker may submit a POST request with a Java object in it to completely compromise a Provider instance of Apache Dubbo, if this instance enables HTTP. This issue affected Apache Dubbo 2.7.0 to 2.7.4, 2.6.0 to 2.6.7, and all 2.5.x versions.