Логотип exploitDog
bind:CVE-2020-26238
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-26238

Количество 3

Количество 3

redhat логотип

CVE-2020-26238

около 5 лет назад

Cron-utils is a Java library to parse, validate, migrate crons as well as get human readable descriptions for them. In cron-utils before version 9.1.3, a template Injection vulnerability is present. This enables attackers to inject arbitrary Java EL expressions, leading to unauthenticated Remote Code Execution (RCE) vulnerability. Only projects using the @Cron annotation to validate untrusted Cron expressions are affected. This issue was patched in version 9.1.3.

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2020-26238

около 5 лет назад

Cron-utils is a Java library to parse, validate, migrate crons as well as get human readable descriptions for them. In cron-utils before version 9.1.3, a template Injection vulnerability is present. This enables attackers to inject arbitrary Java EL expressions, leading to unauthenticated Remote Code Execution (RCE) vulnerability. Only projects using the @Cron annotation to validate untrusted Cron expressions are affected. This issue was patched in version 9.1.3.

CVSS3: 7.9
EPSS: Низкий
github логотип

GHSA-pfj3-56hm-jwq5

около 5 лет назад

Template injection in cron-utils

CVSS3: 7.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2020-26238

Cron-utils is a Java library to parse, validate, migrate crons as well as get human readable descriptions for them. In cron-utils before version 9.1.3, a template Injection vulnerability is present. This enables attackers to inject arbitrary Java EL expressions, leading to unauthenticated Remote Code Execution (RCE) vulnerability. Only projects using the @Cron annotation to validate untrusted Cron expressions are affected. This issue was patched in version 9.1.3.

CVSS3: 8.1
6%
Низкий
около 5 лет назад
nvd логотип
CVE-2020-26238

Cron-utils is a Java library to parse, validate, migrate crons as well as get human readable descriptions for them. In cron-utils before version 9.1.3, a template Injection vulnerability is present. This enables attackers to inject arbitrary Java EL expressions, leading to unauthenticated Remote Code Execution (RCE) vulnerability. Only projects using the @Cron annotation to validate untrusted Cron expressions are affected. This issue was patched in version 9.1.3.

CVSS3: 7.9
6%
Низкий
около 5 лет назад
github логотип
GHSA-pfj3-56hm-jwq5

Template injection in cron-utils

CVSS3: 7.9
6%
Низкий
около 5 лет назад

Уязвимостей на страницу