GHSA-6pqx-v9g4-5hc8

Suggest an improvement
Source
https://github.com/advisories/GHSA-6pqx-v9g4-5hc8
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/12/GHSA-6pqx-v9g4-5hc8/GHSA-6pqx-v9g4-5hc8.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-6pqx-v9g4-5hc8
Aliases
Published
2023-12-02T00:31:05Z
Modified
2024-02-16T08:20:50.353793Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Jupiter allows attackers to execute arbitrary commands via sending a crafted RPC request
Details

A deserialization vulnerability in Jupiter v1.3.1 allows attackers to execute arbitrary commands via sending a crafted RPC request.

Database specific
{
    "nvd_published_at": "2023-12-01T23:15:07Z",
    "severity": "CRITICAL",
    "github_reviewed_at": "2023-12-04T23:13:37Z",
    "github_reviewed": true,
    "cwe_ids": [
        "CWE-502",
        "CWE-94"
    ]
}
References

Affected packages

Maven / org.jupiter-rpc:jupiter-rpc

Package

Name
org.jupiter-rpc:jupiter-rpc
View open source insights on deps.dev
Purl
pkg:maven/org.jupiter-rpc/jupiter-rpc

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
1.3.1

Affected versions

1.*

1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18.Beta
1.2.18.Beta2
1.2.18.Beta3
1.2.18.Beta4
1.2.18
1.2.19.Beta1
1.2.19.Beta2
1.2.19.Beta3
1.2.19
1.2.20
1.2.21
1.2.22
1.2.23
1.2.24
1.2.25
1.2.26
1.3.0
1.3.1-beta-1
1.3.1-beta-2
1.3.1