CVE-2022-31764
Apache ShardingSphere ElasticJob-UI allows RCE via event trace data source JDBC
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The Lite UI of Apache ShardingSphere ElasticJob-UI allows an attacker to perform RCE by constructing a special JDBC URL of H2 database. This issue affects Apache ShardingSphere ElasticJob-UI version 3.0.1 and prior versions. This vulnerability has been fixed in ElasticJob-UI 3.0.2.
The premise of this attack is that the attacker has obtained the account and password. Otherwise, the attacker cannot perform this attack.
The Lite UI of Apache ShardingSphere ElasticJob-UI allows an attacker to perform RCE by constructing a special JDBC URL of H2 database. This issue affects Apache ShardingSphere ElasticJob-UI version 3.0.1 and prior versions. This vulnerability has been fixed in ElasticJob-UI 3.0.2. The premise of this attack is that the attacker has obtained the account and password. Otherwise, the attacker cannot perform this attack.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2022-05-27 CVE Reserved
- 2025-02-06 CVE Published
- 2025-02-06 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-913: Improper Control of Dynamically-Managed Code Resources
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://lists.apache.org/thread/pg0k223m4hsnnzg4nh7lxvdxxgbkrlqb | 2025-02-06 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Apache Software Foundation Search vendor "Apache Software Foundation" | Apache ShardingSphere ElasticJob-UI Search vendor "Apache Software Foundation" for product "Apache ShardingSphere ElasticJob-UI" | >= 3.0.0 <= 3.0.1 Search vendor "Apache Software Foundation" for product "Apache ShardingSphere ElasticJob-UI" and version " >= 3.0.0 <= 3.0.1" | en |
Affected
|