A deserialization vulnerability existed in dubbo hessian-lite 3.2.11 and its earlier versions, which could lead to malicious code execution. Most Dubbo users use Hessian2 as the default serialization/deserialization protocol, during Hessian catch unexpected exceptions, Hessian will log out some imformation for users, which may cause remote command execution. This issue affects Apache Dubbo Apache Dubbo 2.6.x versions prior to 2.6.12; Apache Dubbo 2.7.x versions prior to 2.7.15; Apache Dubbo 3.0.x versions prior to 3.0.5.
{
"cpe": "cpe:2.3:a:apache:dubbo:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "2.6.0"
},
{
"fixed": "2.6.12"
},
{
"introduced": "2.7.0"
},
{
"fixed": "2.7.15"
},
{
"introduced": "3.0.0"
},
{
"fixed": "3.0.5"
}
],
"source": "CPE_RANGE"
}
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-43297.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"105840630700339680499587063123684625926",
"338644187472447787987938570339410852631",
"131080408623506511893947111063167689945",
"214913382123752458605065966920144601353",
"210743646578065676550138105332509893397",
"207005849591186049572499283309734798720",
"165932533642151191412722492371595439730",
"332532369984194475588205298736207604634",
"268035562091688739856543318066397981857",
"331790950058564299213880782917657254388",
"186973334003135703918455472595167818773",
"305840179484634995596217065496205698801",
"165739431391521117050595382396963516342",
"106507069646596523408443142087424393425",
"118678271510876746662388067530704093903",
"314884748488327431603463680917592423137",
"146193997883203382372226884992029619057",
"51570976161121142302114634605899482046",
"267434272079469739146106689252647123386",
"8478493813084372581302047240990396732",
"288811600041105311464382020818409564746"
],
"threshold": 0.9
},
"id": "CVE-2021-43297-032e5d74",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/apache/dubbo/commit/2759f386b1c91f284d2afbb478b6a1943885ce65",
"target": {
"file": "dubbo-rpc/dubbo-rpc-api/src/main/java/org/apache/dubbo/rpc/AsyncRpcResult.java"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"205216969727307634627776840998914543689",
"132244853572873864573296812487824814801",
"8563150917294067192911032742919964366",
"202652800233036647310692047233567457327",
"116574010039281850850627835662267414653",
"223056911161956020832380716176204702307",
"54699785155604460105040368859280286859",
"124918233140311597729277583245647278046",
"265171681208951630768623634046160723358",
"225315504622788064166916335270678441440",
"141701701996780571839202354528887082449",
"9820171954733217094180425034238111089",
"41705223910076413988778339700619732534",
"217130022915471000961987060886260616716"
],
"threshold": 0.9
},
"id": "CVE-2021-43297-0ecefdc4",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/apache/dubbo/commit/2759f386b1c91f284d2afbb478b6a1943885ce65",
"target": {
"file": "dubbo-rpc/dubbo-rpc-api/src/main/java/org/apache/dubbo/rpc/proxy/AbstractProxyInvoker.java"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "10916452516957828174119756368213954592",
"length": 269
},
"id": "CVE-2021-43297-257835e5",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/apache/dubbo/commit/2759f386b1c91f284d2afbb478b6a1943885ce65",
"target": {
"file": "dubbo-rpc/dubbo-rpc-api/src/main/java/org/apache/dubbo/rpc/proxy/AbstractProxyInvoker.java",
"function": "wrapWithFuture"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"293176510030815975789118227261394613959",
"331953475509253397806924779757875967696",
"264541048000121027869602483486468862926",
"179891937111235898691967899612052937601",
"36470830381927990222436476848444329608",
"262878325337054888967946864980030458227",
"306598662018601722260875881668706936459",
"173534407568345480375988158036203312187",
"150879719485051864383752679961313215040",
"22666679620504626611509524201599097850",
"297370285760819126579154452576621599544",
"22571301416349558352793316088621332691",
"206269527738873993184190081225938998967",
"21701653056599239398438848445525310964",
"27791379707522226525325466473314219793",
"121448794538809644192356450150498143870",
"310938730892625379845517321290950389034",
"58019523370786681764792354929735316719",
"131832052696964234849173577515462032908",
"33332752842896948208806861758103225638",
"124121690923850682252668110135835033950",
"96105078966704778328765023539606587197",
"78666222448426893838594570171929114493",
"293404170188364659044249248303629991112",
"103607476654181409557062922730298086983"
],
"threshold": 0.9
},
"id": "CVE-2021-43297-28c519a6",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/apache/dubbo/commit/2759f386b1c91f284d2afbb478b6a1943885ce65",
"target": {
"file": "dubbo-cluster/src/main/java/org/apache/dubbo/rpc/cluster/filter/support/ConsumerContextFilter.java"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "303872633433963096897253945752040244498",
"length": 73
},
"id": "CVE-2021-43297-2c6ee0a7",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/apache/dubbo/commit/2759f386b1c91f284d2afbb478b6a1943885ce65",
"target": {
"file": "dubbo-rpc/dubbo-rpc-api/src/main/java/org/apache/dubbo/rpc/RpcContext.java",
"function": "restoreServiceContext"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"313842595267939949215225802682386360180",
"212771888116420530352496202395584619732",
"110756913046453172936578992085251048553",
"236768599256230195321433013154863858669",
"86540806357342043661392538326792773701",
"155714020009224661890661962222181688724",
"83161078927778752442441961346735927819",
"67278680192861706318123274608517268681",
"240074993872873518167090268634511395345",
"260106503715508389416711320834768883758",
"225788843117954616432587329860690549747"
],
"threshold": 0.9
},
"id": "CVE-2021-43297-2fb37910",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/apache/dubbo/commit/2759f386b1c91f284d2afbb478b6a1943885ce65",
"target": {
"file": "dubbo-rpc/dubbo-rpc-api/src/test/java/org/apache/dubbo/rpc/filter/ContextFilterTest.java"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "227658698285021079233010779295278114272",
"length": 1294
},
"id": "CVE-2021-43297-323816aa",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/apache/dubbo/commit/2759f386b1c91f284d2afbb478b6a1943885ce65",
"target": {
"file": "dubbo-cluster/src/main/java/org/apache/dubbo/rpc/cluster/filter/support/ConsumerContextFilter.java",
"function": "invoke"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "292401055867031279936971919909632536135",
"length": 63
},
"id": "CVE-2021-43297-426ab810",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/apache/dubbo/commit/2759f386b1c91f284d2afbb478b6a1943885ce65",
"target": {
"file": "dubbo-rpc/dubbo-rpc-api/src/main/java/org/apache/dubbo/rpc/RpcContext.java",
"function": "storeContext"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "41746726805890971404070330698636510201",
"length": 181
},
"id": "CVE-2021-43297-45746a12",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/apache/dubbo/commit/2759f386b1c91f284d2afbb478b6a1943885ce65",
"target": {
"file": "dubbo-rpc/dubbo-rpc-api/src/main/java/org/apache/dubbo/rpc/RpcServiceContext.java",
"function": "isValid"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "114454379834248109219271443641648327489",
"length": 126
},
"id": "CVE-2021-43297-4c4ea571",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/apache/dubbo/commit/2759f386b1c91f284d2afbb478b6a1943885ce65",
"target": {
"file": "dubbo-cluster/src/main/java/org/apache/dubbo/rpc/cluster/filter/support/ConsumerContextFilter.java",
"function": "onResponse"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "305381435003790316064103247750575629407",
"length": 70
},
"id": "CVE-2021-43297-4e49846e",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/apache/dubbo/commit/2759f386b1c91f284d2afbb478b6a1943885ce65",
"target": {
"file": "dubbo-rpc/dubbo-rpc-api/src/main/java/org/apache/dubbo/rpc/RpcContext.java",
"function": "restoreServerContext"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "219701883906413027363487897892672658447",
"length": 126
},
"id": "CVE-2021-43297-52fa674f",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/apache/dubbo/commit/2759f386b1c91f284d2afbb478b6a1943885ce65",
"target": {
"file": "dubbo-rpc/dubbo-rpc-api/src/main/java/org/apache/dubbo/rpc/filter/ContextFilter.java",
"function": "onResponse"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "267108839850408299641894773591832191207",
"length": 366
},
"id": "CVE-2021-43297-64bf7123",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/apache/dubbo/commit/2759f386b1c91f284d2afbb478b6a1943885ce65",
"target": {
"file": "dubbo-rpc/dubbo-rpc-api/src/main/java/org/apache/dubbo/rpc/RpcServiceContext.java",
"function": "copyOf"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "36930855333203542732853002669051907457",
"length": 368
},
"id": "CVE-2021-43297-65915ebc",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/apache/dubbo/commit/2759f386b1c91f284d2afbb478b6a1943885ce65",
"target": {
"file": "dubbo-rpc/dubbo-rpc-api/src/main/java/org/apache/dubbo/rpc/AsyncRpcResult.java",
"function": "whenCompleteWithContext"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"79703821070222624813692560548580687592",
"132427287293822652226931821277755333496",
"68581735431841932732818927176790831479",
"317084027041293982344518398080211775240",
"79232349151014864518944208050090280161",
"140377403469601759968703050106041961465",
"86790872893028705253800806592911903555",
"315932684506329625029999593840542627749",
"289990169505914669402762579821766767358",
"241873420012026724810070021099182355105",
"285812578698747385318471625787238873785",
"64638237182214631644387795063161013265",
"166262039053358778984088161518201565808",
"126601816775556823235584891546194757827"
],
"threshold": 0.9
},
"id": "CVE-2021-43297-69f1991b",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/apache/dubbo/commit/2759f386b1c91f284d2afbb478b6a1943885ce65",
"target": {
"file": "dubbo-rpc/dubbo-rpc-api/src/main/java/org/apache/dubbo/rpc/RpcServiceContext.java"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "222450904346959811097847886825087342572",
"length": 62
},
"id": "CVE-2021-43297-71b543bb",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/apache/dubbo/commit/2759f386b1c91f284d2afbb478b6a1943885ce65",
"target": {
"file": "dubbo-cluster/src/main/java/org/apache/dubbo/rpc/cluster/filter/support/ConsumerContextFilter.java",
"function": "onError"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "78401707096876543916541051117229897865",
"length": 326
},
"id": "CVE-2021-43297-8c41a60f",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/apache/dubbo/commit/2759f386b1c91f284d2afbb478b6a1943885ce65",
"target": {
"file": "dubbo-rpc/dubbo-rpc-api/src/main/java/org/apache/dubbo/rpc/AsyncRpcResult.java",
"function": "AsyncRpcResult"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "222450904346959811097847886825087342572",
"length": 62
},
"id": "CVE-2021-43297-9bffe1be",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/apache/dubbo/commit/2759f386b1c91f284d2afbb478b6a1943885ce65",
"target": {
"file": "dubbo-rpc/dubbo-rpc-api/src/main/java/org/apache/dubbo/rpc/filter/ContextFilter.java",
"function": "onError"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "232928962331849494081982080094731679511",
"length": 1443
},
"id": "CVE-2021-43297-a1190fd5",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/apache/dubbo/commit/2759f386b1c91f284d2afbb478b6a1943885ce65",
"target": {
"file": "dubbo-rpc/dubbo-rpc-api/src/main/java/org/apache/dubbo/rpc/filter/ContextFilter.java",
"function": "invoke"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "204796693370845964946967049677394935993",
"length": 241
},
"id": "CVE-2021-43297-a17ff7cf",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/apache/dubbo/commit/2759f386b1c91f284d2afbb478b6a1943885ce65",
"target": {
"file": "dubbo-rpc/dubbo-rpc-api/src/main/java/org/apache/dubbo/rpc/RpcContext.java",
"function": "RestoreContext"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "35431035662239537151611546004125953405",
"length": 127
},
"id": "CVE-2021-43297-a4c766e5",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/apache/dubbo/commit/2759f386b1c91f284d2afbb478b6a1943885ce65",
"target": {
"file": "dubbo-rpc/dubbo-rpc-api/src/main/java/org/apache/dubbo/rpc/AsyncContextImpl.java",
"function": "AsyncContextImpl"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "264426288980229127012500377694968694878",
"length": 75
},
"id": "CVE-2021-43297-a9453a58",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/apache/dubbo/commit/2759f386b1c91f284d2afbb478b6a1943885ce65",
"target": {
"file": "dubbo-rpc/dubbo-rpc-api/src/main/java/org/apache/dubbo/rpc/RpcContext.java",
"function": "restoreClientAttachment"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"142944069142590076085242196513318778316",
"228569324429053942438000357196513600994",
"335156520265055274876816943449165382645",
"69649769897937990642464151838473760152",
"5793383407649166116541013463189126905",
"167857377857751518025668402539575492260",
"46471460789370255789444796363624449441",
"241241915638488127090739660737333293474",
"114149933109488288454662022310703526060",
"31714254690290386049791703974233884432",
"307547701943312556487540124050662753939",
"148491311000198503506551176004481723852",
"131832052696964234849173577515462032908",
"216170105273568253247951257561001927176",
"278553408723394725839155906333567676732",
"111376632099675263389225342341130202335",
"146894469873756514963110255733904853441",
"293404170188364659044249248303629991112",
"103607476654181409557062922730298086983"
],
"threshold": 0.9
},
"id": "CVE-2021-43297-a946e90c",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/apache/dubbo/commit/2759f386b1c91f284d2afbb478b6a1943885ce65",
"target": {
"file": "dubbo-rpc/dubbo-rpc-api/src/main/java/org/apache/dubbo/rpc/filter/ContextFilter.java"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "123325068819178926985155564654410178568",
"length": 75
},
"id": "CVE-2021-43297-ad00ca54",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/apache/dubbo/commit/2759f386b1c91f284d2afbb478b6a1943885ce65",
"target": {
"file": "dubbo-rpc/dubbo-rpc-api/src/main/java/org/apache/dubbo/rpc/RpcContext.java",
"function": "restoreServerAttachment"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "310791806821536478840920833413641862106",
"length": 376
},
"id": "CVE-2021-43297-b1badc67",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/apache/dubbo/commit/2759f386b1c91f284d2afbb478b6a1943885ce65",
"target": {
"file": "dubbo-rpc/dubbo-rpc-api/src/main/java/org/apache/dubbo/rpc/RpcContext.java",
"function": "restore"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"15806291238891691852664257898876085261",
"265713900719561754449007013681906341965",
"210602407268708043078564748390784401376",
"101124603916875955794250627116932757790"
],
"threshold": 0.9
},
"id": "CVE-2021-43297-c50aeb6c",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/apache/dubbo/commit/2759f386b1c91f284d2afbb478b6a1943885ce65",
"target": {
"file": "dubbo-rpc/dubbo-rpc-api/src/main/java/org/apache/dubbo/rpc/AsyncContextImpl.java"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"82456097135638718451504539061298578467",
"113470041640632816903589270538624124591",
"311393523611687486326278158793396990612",
"139463074273790022910610158731664050839",
"257975617583779955863135617977379481058",
"338912733359767556340295556987328815730",
"310885840199633075929534450602109546856",
"37564808720148482714851817658044499166",
"27105784179964577400039013434469815317",
"90176748504287863595757784180916797101",
"62796119244303814524843490837342832360",
"10608411320373178412104033734150121363",
"122144683933971358555663579494239437642",
"275557330661365490461954069618201495440",
"338955508987970182777644295927622165513",
"252947152413973249810378185752487325490",
"98684472048494158767641780905888535866",
"5233651666600705931913496415493692001",
"160238822385599510335062203183328026108",
"155286655799873167242687149824860969754",
"165400558924703588245733655139908450015",
"97889583138240927109714950263349468043",
"165727141109020004469817114425579546563",
"32035938045450749084774598192091909772",
"169636273230382879832223910258258666283",
"18718890277512500824709669108142038068",
"174414011940703830733035502912007794722",
"151155449565317926876896328671543600122",
"102570034485882783637515117363185649720",
"265036147997348833615359820367902188024",
"27333563217619561894398494388331676451",
"112176714312051788397585869169117480916",
"201357998480209266067135530991659250751",
"33292969868728128046708850803395685454",
"165335811040449477119972985782065293910",
"231755894454749852077532873326558451854",
"143748562847923986400311554335491153456",
"65562132287176671029658032330788988891",
"270308935011995943409159259349824454126",
"79696991224054805891115625966661735407",
"223496598167403795381423357763646789144",
"41301436958358229725496523289295775771",
"275514147810505410193671650085648110102",
"77491687001067483017168795414247115118",
"122083894427646440529143594062565251155",
"9785936722009502462222794975325040066",
"208433229427780829970220322224966382920"
],
"threshold": 0.9
},
"id": "CVE-2021-43297-e4c4010a",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/apache/dubbo/commit/2759f386b1c91f284d2afbb478b6a1943885ce65",
"target": {
"file": "dubbo-rpc/dubbo-rpc-api/src/main/java/org/apache/dubbo/rpc/RpcContext.java"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "49461203357862445218960661908242713418",
"length": 1066
},
"id": "CVE-2021-43297-e53f6d8c",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/apache/dubbo/commit/2759f386b1c91f284d2afbb478b6a1943885ce65",
"target": {
"file": "dubbo-rpc/dubbo-rpc-api/src/main/java/org/apache/dubbo/rpc/proxy/AbstractProxyInvoker.java",
"function": "invoke"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"273400586906309163864288407849493698563"
],
"threshold": 0.9
},
"id": "CVE-2021-43297-f37604d5",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/apache/dubbo/commit/2759f386b1c91f284d2afbb478b6a1943885ce65",
"target": {
"file": "dubbo-common/src/main/java/org/apache/dubbo/common/constants/CommonConstants.java"
}
}
]
"2026-07-09T00:37:42Z"