GHSA-px4w-rcv2-6x8x

Suggest an improvement
Source
https://github.com/advisories/GHSA-px4w-rcv2-6x8x
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/02/GHSA-px4w-rcv2-6x8x/GHSA-px4w-rcv2-6x8x.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-px4w-rcv2-6x8x
Aliases
Published
2022-02-09T22:19:00Z
Modified
2023-11-08T04:02:43.003658Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Arbitrary code execution in Apache ServiceComb java-chassis
Details

When handler-router component is enabled in servicecomb-java-chassis, authenticated user may inject some data and cause arbitrary code execution. The problem happens in versions between 2.0.0 ~ 2.1.3 and fixed in Apache ServiceComb-Java-Chassis 2.1.5

Database specific
{
    "nvd_published_at": "2021-01-25T10:16:00Z",
    "github_reviewed_at": "2021-04-06T20:02:19Z",
    "severity": "HIGH",
    "github_reviewed": true,
    "cwe_ids": [
        "CWE-502"
    ]
}
References

Affected packages

Maven / org.apache.servicecomb:java-chassis

Package

Name
org.apache.servicecomb:java-chassis
View open source insights on deps.dev
Purl
pkg:maven/org.apache.servicecomb/java-chassis

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.0.0
Fixed
1.3.2

Affected versions

1.*

1.0.0
1.1.0
1.2.0
1.2.1
1.3.0
1.3.1

Maven / org.apache.servicecomb:java-chassis

Package

Name
org.apache.servicecomb:java-chassis
View open source insights on deps.dev
Purl
pkg:maven/org.apache.servicecomb/java-chassis

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.0.0
Fixed
2.1.5

Affected versions

2.*

2.0.0
2.0.1
2.0.2
2.1.0
2.1.1
2.1.2
2.1.3