Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6523-jf4r-c962

Опубликовано: 17 июл. 2024
Источник: github
Github: Прошло ревью
CVSS4: 8.7
CVSS3: 8.8

Описание

Apache StreamPipes has potential remote code execution (RCE) via file upload

Unrestricted Upload of File with dangerous type vulnerability in Apache StreamPipes. Such a dangerous type might be an executable file that may lead to a remote code execution (RCE). The unrestricted upload is only possible for authenticated and authorized users.

This issue affects Apache StreamPipes: through 0.93.0.

Users are recommended to upgrade to version 0.95.0, which fixes the issue.

Пакеты

Наименование

org.apache.streampipes:streampipes-parent

maven
Затронутые версииВерсия исправления

< 0.95.0

0.95.0

Наименование

streampipes

pip
Затронутые версииВерсия исправления

< 0.95.0

0.95.0

EPSS

Процентиль: 82%
0.01796
Низкий

8.7 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 8.8
nvd
больше 1 года назад

Unrestricted Upload of File with dangerous type vulnerability in Apache StreamPipes. Such a dangerous type might be an executable file that may lead to a remote code execution (RCE). The unrestricted upload is only possible for authenticated and authorized users. This issue affects Apache StreamPipes: through 0.93.0. Users are recommended to upgrade to version 0.95.0, which fixes the issue.

EPSS

Процентиль: 82%
0.01796
Низкий

8.7 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-434