CVE-2022-24969: Apache Dubbo
Medium severity, CVSS 6.1. EPSS: 1.8% chance of exploitation in the next 30 days.
bypass CVE-2021-25640 > In Apache Dubbo prior to 2.6.12 and 2.7.15, the usage of parseURL method will lead to the bypass of the white host check which can cause open redirect or SSRF vulnerability.
Affected products
- Apache Dubbo: before 2.6.12 (fixed in 2.6.12); from 2.7.0, before 2.7.15 (fixed in 2.7.15)
Published 2022-06-09. Last modified 2026-06-17.