Cyber Resilience

CVE-2021-30181

Apache Dubbo 2.5.0 – 2.6.10

High EPSS
Published
01 June 2021
Modified
21 November 2024
Patch / advisory
CVSS Score v3.1 9.8
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.61 99.1th percentile
Risk Priority 90 floored blend · peak EPSS

Summary

CVE-2021-30181 is a critical-severity an unspecified weakness vulnerability in Apache Dubbo. Its CVSS base score is 9.8 (Critical).

Operationally, ranked in the top 0.9% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog.

EU & UK References

Vulnerability Data

Apache Dubbo prior to 2.6.9 and 2.7.9 supports Script routing which will enable a customer to route the request to the right server. These rules are used by the customers when making a request in order to find the right…

more

endpoint. When parsing these rules, Dubbo customers use ScriptEngine and run the rule provided by the script which by default may enable executing arbitrary code.

CWE(s)

Related Threats

Likely ATT&CK TechniquesAI

Techniques this vulnerability likely enables, inferred from its description, weakness type, and attributed-actor tradecraft. Confidence is per-technique.

T1059 Command and Scripting Interpreter Executionconfidence: HIGH
Script routing rules are executed via ScriptEngine, directly enabling arbitrary command/script execution.
T1203 Exploitation for Client Execution Executionconfidence: MEDIUM
Malicious script rules can be supplied to trigger client-side code execution when parsed.
inferred from description · MITRE ATT&CK Enterprise v19.0

CVEs Like This One

CVE-2023-23638Same product: Apache Dubbo
CVE-2023-46279Same product: Apache Dubbo
CVE-2021-30180Same product: Apache Dubbo
CVE-2023-29234Same product: Apache Dubbo
CVE-2025-23195Same vendor: Apache
CVE-2024-42362Same vendor: Apache
CVE-2024-29070Same vendor: Apache
CVE-2023-28706Same vendor: Apache
CVE-2024-24773Same vendor: Apache
CVE-2026-56624Same vendor: Apache

Affected Assets

apache
dubbo
2.5.0 — 2.6.10 · 2.7.0 — 2.7.10

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References