CVE-2021-36161: Use of Externally-Controlled Format String
(updated )
A component in Dubbo will try to print the formated string of the input arguments, which will possibly cause RCE for a maliciously customized bean with special toString
method.
References
Detect and mitigate CVE-2021-36161 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →