Apache · Apache Servicecomb-Java-Chassis · CVE-2020-17532
Name of the Vulnerable Software and Affected Versions:
Apache ServiceComb-Java-Chassis versions 2.0.0 through 2.1.3
Description:
The issue allows an authenticated user to inject data and potentially cause arbitrary code execution when the handler-router component is enabled in servicecomb-java-chassis.
Recommendations:
For versions 2.0.0 through 2.1.3, update to Apache ServiceComb-Java-Chassis version 2.1.5 to resolve the issue.