Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2021-25641 PoC — Apache Dubbo 代码问题漏洞

Source
Associated Vulnerability
Title:Apache Dubbo 代码问题漏洞 (CVE-2021-25641)
Description:Apache Dubbo是美国阿帕奇(Apache)基金会的一款基于Java的轻量级RPC(远程过程调用)框架。该产品提供了基于接口的远程呼叫、容错和负载平衡以及自动服务注册和发现等功能。 Apache Dubbo 2.7.8和2.6.9之前版本存在代码问题漏洞,该漏洞源于攻击者利用该漏洞可以通过篡改字节前序标志(也就是不遵循服务器的指令)来选择提供者将使用哪个序列化id。
Description
A Exploit Tool For CVE-2021-25641.
Readme
# CVE-2021-25641
A Exploit Tool For CVE-2021-25641.

All dependencies was packed,You don't care the dependencies problem</br>
If you have dependencies you can just donwload the CVE-2021-25641.jar to run.

## Used for:
Basic dubbo-common <=2.7.3</br>
Dubbo 2.7.0 to 2.7.8</br>
Dubbo 2.6.0 to 2.6.9</br>
Dubbo all 2.5.x versions (not supported by official team any longer)
File Snapshot

[4.0K] /data/pocs/515fd1dd2095dafd85fc58282d21aab097f80f36 ├── [ 52K] asm-5.0.4.jar ├── [ 60K] commons-logging-1.2.jar ├── [ 11K] CVE-2021-25641.jar ├── [2.2M] dubbo-2.7.3.jar ├── [318K] dubbo-common-2.6.9.jar ├── [361K] dubbo-common-2.7.3.jar ├── [159K] dubbo-remoting-api-2.6.9.jar ├── [ 36K] dubbo-remoting-netty4-2.6.9.jar ├── [ 12K] dubbo-serialization-api-2.6.9.jar ├── [528K] fastjson-1.2.46.jar ├── [372K] fst-2.48-jdk-6.jar ├── [236K] gson-2.8.5.jar ├── [231K] hessian-lite-3.2.5.jar ├── [275K] jackson-core-2.8.6.jar ├── [733K] javassist-3.20.0-GA.jar ├── [ 57K] java-util-1.9.0.jar ├── [ 73K] json-io-2.5.1.jar ├── [329K] kryo-4.0.1.jar ├── [104K] kryo-serializers-0.42.jar ├── [470K] log4j-1.2.16.jar ├── [5.6K] minlog-1.3.0.jar ├── [4.2M] netty-all-4.1.60.Final.jar ├── [ 53K] objenesis-2.5.1.jar ├── [ 15K] permit-reflect-0.4.jar ├── [ 371] README.md ├── [ 20K] reflectasm-1.11.3.jar ├── [292K] snakeyaml-1.20.jar ├── [371K] spring-aop-4.3.16.RELEASE.jar ├── [658K] spring-beans-5.1.9.RELEASE.jar ├── [1.1M] spring-context-4.3.16.RELEASE.jar ├── [1.2M] spring-core-5.1.9.RELEASE.jar ├── [266K] spring-expression-4.3.16.RELEASE.jar ├── [ 23K] spring-jcl-5.1.9.RELEASE.jar └── [1.3M] spring-web-5.1.9.RELEASE.jar 0 directories, 34 files
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.