-
CVSS Score
-| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.apache.dubbo:dubbo | maven | >= 2.5.0, < 2.7.15 | 2.7.15 |
| com.alibaba:dubbo | maven | >= 2.5.0, < 2.6.12 | 2.6.12 |
The vulnerability centers around improper URL parsing that bypasses security checks. Both CVE descriptions explicitly name parseURL as the problematic method. While no patch code is available, the consistent attribution across advisories indicates parseURL is the primary vulnerable function. In runtime detection, this method would process malicious URLs during exploitation attempts, making it the key indicator.
Ongoing coverage of React2Shell