Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4vm3-cxh9-9697

Опубликовано: 03 сент. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

Apache OFBiz uses the Birt project plugin (https://eclipse.github.io/birt-website/) to create data visualizations and reports. By leveraging a bug in Birt (https://bugs.eclipse.org/bugs/show_bug.cgi?id=538142) it is possible to perform a remote code execution (RCE) attack in Apache OFBiz, release 18.12.05 and earlier.

Apache OFBiz uses the Birt project plugin (https://eclipse.github.io/birt-website/) to create data visualizations and reports. By leveraging a bug in Birt (https://bugs.eclipse.org/bugs/show_bug.cgi?id=538142) it is possible to perform a remote code execution (RCE) attack in Apache OFBiz, release 18.12.05 and earlier.

EPSS

Процентиль: 79%
0.01285
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-22
CWE-94

Связанные уязвимости

CVSS3: 9.8
nvd
больше 3 лет назад

Apache OFBiz uses the Birt project plugin (https://eclipse.github.io/birt-website/) to create data visualizations and reports. By leveraging a bug in Birt (https://bugs.eclipse.org/bugs/show_bug.cgi?id=538142) it is possible to perform a remote code execution (RCE) attack in Apache OFBiz, release 18.12.05 and earlier.

EPSS

Процентиль: 79%
0.01285
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-22
CWE-94