Apache Dubbo prior to 2.7.9 support Tag routing which will enable a customer to route the request to the right server. These rules are used by the customers when making a request in order to find the right endpoint. When parsing these YAML rules, Dubbo customers may enable calling arbitrary constructors.
{ "nvd_published_at": "2021-06-01T14:15:00Z", "github_reviewed_at": "2021-06-02T20:19:48Z", "severity": "CRITICAL", "github_reviewed": true, "cwe_ids": [ "CWE-444", "CWE-94" ] }