Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-41875

Опубликовано: 23 нояб. 2022
Источник: nvd
CVSS3: 10
CVSS3: 9.8
EPSS Средний

Описание

A remote code execution (RCE) vulnerability in Optica allows unauthenticated attackers to execute arbitrary code via specially crafted JSON payloads. Specially crafted JSON payloads may lead to RCE (remote code execution) on the attacked system running Optica. The vulnerability was patched in v. 0.10.2, where the call to the function oj.load was changed to oj.safe_load.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:airbnb:optica:*:*:*:*:*:*:*:*
Версия до 0.10.2 (исключая)

EPSS

Процентиль: 94%
0.15112
Средний

10 Critical

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-502

EPSS

Процентиль: 94%
0.15112
Средний

10 Critical

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-502