Unsafe deserialization in providers using the Hessian protocol
CVE-2021-36163
What is CVE-2021-36163?
In Apache Dubbo, users may choose to use the Hessian protocol. The Hessian protocol is implemented on top of HTTP and passes the body of a POST request directly to a HessianSkeleton: New HessianSkeleton are created without any configuration of the serialization factory and therefore without applying the dubbo properties for applying allowed or blocked type lists. In addition, the generic service is always exposed and therefore attackers do not need to figure out a valid service/method name pair. This is fixed in 2.7.13, 2.6.10.1

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Apache Dubbo Apache Dubbo 2.7.x <= 2.7.12
Apache Dubbo Apache Dubbo 2.6.x <= 2.6.10
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved