Apache Dubbo prior to 2.7.9 support Tag routing which will enable a customer to route the request to the right server. These rules are used by the customers when making a request in order to find the right endpoint. When parsing these YAML rules, Dubbo customers may enable calling arbitrary constructors.
{
"nvd_published_at": "2021-06-01T14:15:00Z",
"cwe_ids": [
"CWE-444",
"CWE-94"
],
"severity": "CRITICAL",
"github_reviewed_at": "2021-06-02T20:19:48Z",
"github_reviewed": true
}