Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j65f-mvgw-prp2

Опубликовано: 14 мая 2022
Источник: github
Github: Прошло ревью

Описание

Deserialization of Untrusted Data in Apache OpenJPA

The BrokerFactory functionality in Apache OpenJPA 1.x before 1.2.3 and 2.x before 2.2.2 creates local executable JSP files containing logging trace data produced during deserialization of certain crafted OpenJPA objects, which makes it easier for remote attackers to execute arbitrary code by creating a serialized object and leveraging improperly secured server programs.

Пакеты

Наименование

org.apache.openjpa:openjpa

maven
Затронутые версииВерсия исправления

>= 1.0.0, < 1.2.3

1.2.3

Наименование

org.apache.openjpa:openjpa

maven
Затронутые версииВерсия исправления

>= 2.0.0, < 2.2.2

2.2.2

EPSS

Процентиль: 95%
0.09511
Низкий

Дефекты

CWE-502

Связанные уязвимости

ubuntu
около 13 лет назад

The BrokerFactory functionality in Apache OpenJPA 1.x before 1.2.3 and 2.x before 2.2.2 creates local executable JSP files containing logging trace data produced during deserialization of certain crafted OpenJPA objects, which makes it easier for remote attackers to execute arbitrary code by creating a serialized object and leveraging improperly secured server programs.

redhat
около 13 лет назад

The BrokerFactory functionality in Apache OpenJPA 1.x before 1.2.3 and 2.x before 2.2.2 creates local executable JSP files containing logging trace data produced during deserialization of certain crafted OpenJPA objects, which makes it easier for remote attackers to execute arbitrary code by creating a serialized object and leveraging improperly secured server programs.

nvd
около 13 лет назад

The BrokerFactory functionality in Apache OpenJPA 1.x before 1.2.3 and 2.x before 2.2.2 creates local executable JSP files containing logging trace data produced during deserialization of certain crafted OpenJPA objects, which makes it easier for remote attackers to execute arbitrary code by creating a serialized object and leveraging improperly secured server programs.

debian
около 13 лет назад

The BrokerFactory functionality in Apache OpenJPA 1.x before 1.2.3 and ...

EPSS

Процентиль: 95%
0.09511
Низкий

Дефекты

CWE-502