CVE-2022-24969
—CVSS 3.1
6.1 medium
EPSS
2%p77
Published
()
Modified
Description
bypass CVE-2021-25640 > In Apache Dubbo prior to 2.6.12 and 2.7.15, the usage of parseURL method will lead to the bypass of the white host check which can cause open redirect or SSRF vulnerability.
- Vendors
- apache
- Products
- dubbo
- Weakness
- CWE-918, CWE-601
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.