PT-2023-15508 · Jedox · Jedox
CVE-2022-47876
·
Publicado
2023-05-02
·
Atualizado
2025-01-30
CVSS v3.1
9.1
Crítica
| Vetor | AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Jedox versions 2020.2.5
Description
The issue allows remote authenticated users to create jobs that can execute arbitrary code via Groovy scripts. This is related to the integrator component in the affected software.
Recommendations
For version 2020.2.5, consider disabling the Groovy script execution functionality as a temporary workaround until a patch is available. Restrict access to the integrator component to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Jedox