Vulnerability Description
bypass CVE-2021-25640 > In Apache Dubbo prior to 2.6.12 and 2.7.15, the usage of parseURL method will lead to the bypass of the white host check which can cause open redirect or SSRF vulnerability.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Dubbo | < 2.6.12 |
Related Weaknesses (CWE)
References
- https://lists.apache.org/thread/1xbckc3467wfk5r7n2o44r2brdsbwxgrBroken Link
- https://lists.apache.org/thread/1xbckc3467wfk5r7n2o44r2brdsbwxgrBroken Link
FAQ
What is CVE-2022-24969?
CVE-2022-24969 is a vulnerability with a CVSS score of 6.1 (MEDIUM). bypass CVE-2021-25640 > In Apache Dubbo prior to 2.6.12 and 2.7.15, the usage of parseURL method will lead to the bypass of the white host check which can cause open redirect or SSRF vulnerability.
How severe is CVE-2022-24969?
CVE-2022-24969 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-24969?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Dubbo.