PT-2023-31406 · Apache · Maven

Huajie Wang

·

Publicado

2023-12-15

·

Atualizado

2024-01-05

·

CVE-2023-49898

CVSS v3.1

7.2

Alta

VetorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions streampark versions prior to 2.1.2
Description The issue is related to the project module in streampark that integrates Maven's compilation capability. There is no check on the compilation parameters of Maven, allowing attackers to insert commands for remote command execution. The prerequisite for a successful attack is that the user needs to log in to the streampark system and have system-level permissions. Generally, only users of that system have the authorization to log in, and users would not manually input a dangerous operation command. Therefore, the risk level of this issue is very low.
Recommendations All users should upgrade to 2.1.2 to mitigate the risk. As a temporary workaround, consider restricting access to the Maven compilation parameters to minimize the risk of exploitation. Avoid using the settings.xml file in the /usr/share/java/maven-3/conf/ directory with untrusted input until the issue is resolved.

Correção

Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-49898
GHSA-QG44-XQWJ-WC28

Produtos afetados

Maven