PT-2023-24604 · Dataease · Dataease

Luelueking

·

Publicado

2023-06-01

·

Atualizado

2023-06-08

·

CVE-2023-33963

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions DataEase versions prior to 1.18.7
Description A deserialization vulnerability exists in the DataEase datasource, which can be exploited to execute arbitrary code. The issue has been fixed in version 1.18.7. There are no known workarounds aside from upgrading.
Recommendations For versions prior to 1.18.7, upgrade to version 1.18.7 or later to resolve the issue. As a temporary workaround, consider restricting access to the DataEase datasource until the upgrade can be applied.

Exploit

Correção

Deserialization of Untrusted Data

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-33963
GHSA-M26J-GH4M-XH9F

Produtos afetados

Dataease