Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-99px-7724-484v

Опубликовано: 13 сент. 2021
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

Remote Code Execution in Any23

A Remote Code Execution (RCE) vulnerability was discovered in the Any23 YAMLExtractor.java file and is known to affect Any23 versions < 2.5. RCE vulnerabilities allow a malicious actor to execute any code of their choice on a remote machine over LAN, WAN, or internet. RCE belongs to the broader class of arbitrary code execution (ACE) vulnerabilities.

Пакеты

Наименование

org.apache.any23:apache-any23

maven
Затронутые версииВерсия исправления

< 2.5

2.5

EPSS

Процентиль: 89%
0.04295
Низкий

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
nvd
больше 4 лет назад

A Remote Code Execution (RCE) vulnerability was discovered in the Any23 YAMLExtractor.java file and is known to affect Any23 versions < 2.5. RCE vulnerabilities allow a malicious actor to execute any code of their choice on a remote machine over LAN, WAN, or internet. RCE belongs to the broader class of arbitrary code execution (ACE) vulnerabilities.

EPSS

Процентиль: 89%
0.04295
Низкий

9.8 Critical

CVSS3