NULL Pointer Dereference Affecting org.apache.dubbo:dubbo-common package, versions [,2.7.15) [3.0.0,3.0.2)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-JAVA-ORGAPACHEDUBBO-1315839
- published 18 Oct 2021
- disclosed 1 Jul 2021
- credit Unknown
How to fix?
Upgrade org.apache.dubbo:dubbo-common
to version 2.7.15, 3.0.2 or higher.
Overview
org.apache.dubbo:dubbo-common is a high-performance, java based, open source RPC framework.
Affected versions of this package are vulnerable to NULL Pointer Dereference. When the parseURL()
/parseURLs()
functions receive an empty address as an argument, or getDefaultExtension()
return a null valued defaultextension
, a null pointer dereference might occur leading to a potential crash.
CVSS Scores
version 3.1