Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x943-vqmm-c5qp

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.9

Описание

Eclipse Keti is a service that was designed to protect RESTfuls API using Attribute Based Access Control (ABAC). In Keti a user able to create Policy Sets can run arbitrary code by sending malicious Groovy scripts which will escape the configured Groovy sandbox. This vulnerability is known to exist in the latest commit at the time of writing this CVE (commit a1c8dbe). For more details see the referenced GHSL-2021-063.

Eclipse Keti is a service that was designed to protect RESTfuls API using Attribute Based Access Control (ABAC). In Keti a user able to create Policy Sets can run arbitrary code by sending malicious Groovy scripts which will escape the configured Groovy sandbox. This vulnerability is known to exist in the latest commit at the time of writing this CVE (commit a1c8dbe). For more details see the referenced GHSL-2021-063.

EPSS

Процентиль: 55%
0.0033
Низкий

9.9 Critical

CVSS3

Дефекты

CWE-917
CWE-94

Связанные уязвимости

CVSS3: 8.2
nvd
больше 4 лет назад

Eclipse Keti is a service that was designed to protect RESTfuls API using Attribute Based Access Control (ABAC). In Keti a user able to create Policy Sets can run arbitrary code by sending malicious Groovy scripts which will escape the configured Groovy sandbox. This vulnerability is known to exist in the latest commit at the time of writing this CVE (commit a1c8dbe). For more details see the referenced GHSL-2021-063.

EPSS

Процентиль: 55%
0.0033
Низкий

9.9 Critical

CVSS3

Дефекты

CWE-917
CWE-94