Описание
When handler-router component is enabled in servicecomb-java-chassis, authenticated user may inject some data and cause arbitrary code execution. The problem happens in versions between 2.0.0 ~ 2.1.3 and fixed in Apache ServiceComb-Java-Chassis 2.1.5
Ссылки
- Mailing ListPatchVendor Advisory
- Mailing ListThird Party Advisory
- Mailing ListPatchVendor Advisory
- Mailing ListThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 2.0.0 (включая) до 2.1.5 (исключая)
cpe:2.3:a:apache:java_chassis:*:*:*:*:*:*:*:*
EPSS
Процентиль: 86%
0.02854
Низкий
8.8 High
CVSS3
6 Medium
CVSS2
Дефекты
CWE-20
CWE-502
Связанные уязвимости
CVSS3: 8.8
github
почти 4 года назад
Arbitrary code execution in Apache ServiceComb java-chassis
EPSS
Процентиль: 86%
0.02854
Низкий
8.8 High
CVSS3
6 Medium
CVSS2
Дефекты
CWE-20
CWE-502