Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-23463

Опубликовано: 24 сент. 2022
Источник: nvd
CVSS3: 9.4
CVSS3: 9.8
EPSS Низкий

Описание

Nepxion Discovery is a solution for Spring Cloud. Discover is vulnerable to SpEL Injection in discovery-commons. DiscoveryExpressionResolver’s eval method is evaluating expression with a StandardEvaluationContext, allowing the expression to reach and interact with Java classes such as java.lang.Runtime, leading to Remote Code Execution. There is no patch available for this issue at time of publication. There are no known workarounds.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:nepxion:discovery:*:*:*:*:*:spring_cloud:*:*
Версия до 6.16.2 (включая)

EPSS

Процентиль: 79%
0.01275
Низкий

9.4 Critical

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-917

Связанные уязвимости

CVSS3: 9.4
github
больше 3 лет назад

Nepxion Discovery vulnerable to SpEL Injection leading to Remote Code Execution

EPSS

Процентиль: 79%
0.01275
Низкий

9.4 Critical

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-917