Apache bRPC是美国阿帕奇(Apache)基金会的用于构建可靠和高性能服务的工业级 RPC 框架。 Apache bRPC 1.15.0之前版本存在安全漏洞,该漏洞源于堆性能分析器内置服务未验证用户提供的extra_options参数,可能导致远程命令注入攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache bRPC | 1.11.0 ~ 1.15.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | CVE-2025-60021 PoC: Apache bRPC Heap Profiler Command Injection | https://github.com/ninjazan420/CVE-2025-60021-PoC-Apache-bRPC-Heap-Profiler-Command-Injection | POC Details |
| 2 | CVE-2025-60021 | https://github.com/Mefhika120/Ashwesker-CVE-2025-60021 | POC Details |
No public POC found.
Login to generate AI POC| CVE-2025-68438 | Apache Airflow: Secrets in rendered templates could contain parts of sensitive values when | |
| CVE-2025-68675 | Apache Airflow: proxy credentials for various providers might leak in task logs |
No comments yet