Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q979-9m39-23mq

Опубликовано: 25 сент. 2022
Источник: github
Github: Прошло ревью
CVSS3: 9.4

Описание

Nepxion Discovery vulnerable to SpEL Injection leading to Remote Code Execution

Nepxion Discovery is a solution for Spring Cloud. Discovery is vulnerable to SpEL Injection in discovery-commons. DiscoveryExpressionResolver’s eval method is evaluating expression with a StandardEvaluationContext, allowing the expression to reach and interact with Java classes such as java.lang.Runtime, leading to Remote Code Execution. There is no patch available for this issue at time of publication. There are no known workarounds.

Пакеты

Наименование

com.nepxion:discovery

maven
Затронутые версииВерсия исправления

<= 6.16.2

Отсутствует

EPSS

Процентиль: 79%
0.01275
Низкий

9.4 Critical

CVSS3

Дефекты

CWE-917

Связанные уязвимости

CVSS3: 9.4
nvd
больше 3 лет назад

Nepxion Discovery is a solution for Spring Cloud. Discover is vulnerable to SpEL Injection in discovery-commons. DiscoveryExpressionResolver’s eval method is evaluating expression with a StandardEvaluationContext, allowing the expression to reach and interact with Java classes such as java.lang.Runtime, leading to Remote Code Execution. There is no patch available for this issue at time of publication. There are no known workarounds.

EPSS

Процентиль: 79%
0.01275
Низкий

9.4 Critical

CVSS3

Дефекты

CWE-917