Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j7qq-8hrp-f3j8

Опубликовано: 19 мар. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 9

Описание

An issue was discovered in Exasol jdbc driver 24.2.0. Attackers can inject malicious parameters into the JDBC URL, triggering JNDI injection during the process when the JDBC Driver uses this URL to connect to the database. This can further lead to remote code execution vulnerability.

An issue was discovered in Exasol jdbc driver 24.2.0. Attackers can inject malicious parameters into the JDBC URL, triggering JNDI injection during the process when the JDBC Driver uses this URL to connect to the database. This can further lead to remote code execution vulnerability.

EPSS

Процентиль: 66%
0.00508
Низкий

9 Critical

CVSS3

Дефекты

CWE-471
CWE-94

Связанные уязвимости

CVSS3: 8.3
nvd
11 месяцев назад

An issue was discovered in Exasol JDBC driver before 24.2.1 (2024-12-10). Attackers can inject malicious parameters into the JDBC URL, triggering JNDI injection during the process when the JDBC Driver uses this URL to connect to the database. This can further lead to remote code execution.

EPSS

Процентиль: 66%
0.00508
Низкий

9 Critical

CVSS3

Дефекты

CWE-471
CWE-94