CVE-2021-43297 is a critical deserialization vulnerability in Apache Dubbo, affecting versions 2.6.x prior to 2.6.12, 2.7.x prior to 2.7.15, and 3.0.x prior to 3.0.5. This flaw, stemming from the hessian-lite library, allows for remote code execution due to improper handling of unexpected exceptions during Hessian serialization/deserialization. With a CVSS score of 9.8 (Critical), it presents a severe risk as it can be exploited remotely without authentication and leads to complete compromise of confidentiality, integrity, and availability. While no active exploitation, public exploit code, or significant community discussion has been observed, its high EPSS score and FAUCET Risk Score indicate a substantial potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.6.0, < 2.6.12CPE matchmatch criteria | cpe:2.3:a:apache:dubbo:*:*:*:*:*:*:*:* | ||
>= 2.7.0, < 2.7.15CPE matchmatch criteria | cpe:2.3:a:apache:dubbo:*:*:*:*:*:*:*:* | ||
>= 3.0.0, < 3.0.5CPE matchmatch criteria | cpe:2.3:a:apache:dubbo:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.