NULL Pointer Dereference Affecting org.apache.dubbo:dubbo-common Open this link in a new tab package, versions [,3.0.2)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.Test your applications
18 Oct 2021
1 Jul 2021
Introduced: 1 Jul 2021CWE-476 Open this link in a new tab
How to fix?
org.apache.dubbo:dubbo-common to version 3.0.2 or higher.
org.apache.dubbo:dubbo-common is a high-performance, java based, open source RPC framework.
Affected versions of this package are vulnerable to NULL Pointer Dereference. When the
parseURLs() functions receive an empty address as an argument, or
getDefaultExtension() return a null valued
defaultextension, a null pointer dereference might occur leading to a potential crash.