Apache · Apache Shardingsphere Elasticjob-Ui · CVE-2022-31764
Name of the Vulnerable Software and Affected Versions:
Apache ShardingSphere ElasticJob-UI versions prior to 3.0.2
Description:
The issue allows an attacker to perform remote code execution (RCE) by constructing a special JDBC URL of the H2 database. The premise of this attack is that the attacker has obtained the account and password, as otherwise, the attack cannot be performed.
Recommendations:
For versions prior to 3.0.2, update to ElasticJob-UI 3.0.2 to resolve the issue. As a temporary workaround, consider restricting access to the H2 database or limiting the construction of special JDBC URLs until the update can be applied.