Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j65f-mvgw-prp2

Опубликовано: 14 мая 2022
Источник: github
Github: Прошло ревью

Описание

Deserialization of Untrusted Data in Apache OpenJPA

The BrokerFactory functionality in Apache OpenJPA 1.x before 1.2.3 and 2.x before 2.2.2 creates local executable JSP files containing logging trace data produced during deserialization of certain crafted OpenJPA objects, which makes it easier for remote attackers to execute arbitrary code by creating a serialized object and leveraging improperly secured server programs.

Пакеты

Наименование

org.apache.openjpa:openjpa

maven
Затронутые версииВерсия исправления

>= 1.0.0, < 1.2.3

1.2.3

Наименование

org.apache.openjpa:openjpa

maven
Затронутые версииВерсия исправления

>= 2.0.0, < 2.2.2

2.2.2

EPSS

Процентиль: 93%
0.10049
Средний

Дефекты

CWE-502

Связанные уязвимости

ubuntu
больше 12 лет назад

The BrokerFactory functionality in Apache OpenJPA 1.x before 1.2.3 and 2.x before 2.2.2 creates local executable JSP files containing logging trace data produced during deserialization of certain crafted OpenJPA objects, which makes it easier for remote attackers to execute arbitrary code by creating a serialized object and leveraging improperly secured server programs.

redhat
больше 12 лет назад

The BrokerFactory functionality in Apache OpenJPA 1.x before 1.2.3 and 2.x before 2.2.2 creates local executable JSP files containing logging trace data produced during deserialization of certain crafted OpenJPA objects, which makes it easier for remote attackers to execute arbitrary code by creating a serialized object and leveraging improperly secured server programs.

nvd
больше 12 лет назад

The BrokerFactory functionality in Apache OpenJPA 1.x before 1.2.3 and 2.x before 2.2.2 creates local executable JSP files containing logging trace data produced during deserialization of certain crafted OpenJPA objects, which makes it easier for remote attackers to execute arbitrary code by creating a serialized object and leveraging improperly secured server programs.

debian
больше 12 лет назад

The BrokerFactory functionality in Apache OpenJPA 1.x before 1.2.3 and ...

EPSS

Процентиль: 93%
0.10049
Средний

Дефекты

CWE-502