PT-2022-16005 · Nepxion · Nepxion Discovery

Jorge Rosillo

+1

·

Published

2022-09-24

·

Updated

2022-09-28

·

CVE-2022-23463

CVSS v3.1

9.4

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions Nepxion Discovery (affected versions not specified)
Description The issue is related to SpEL Injection in discovery-commons, where the DiscoveryExpressionResolver’s eval method evaluates expressions with a StandardEvaluationContext. This allows the expression to interact with Java classes, such as java.lang.Runtime, leading to Remote Code Execution. There are no known workarounds for this issue.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Weakness Enumeration

Related Identifiers

CVE-2022-23463
GHSA-Q979-9M39-23MQ

Affected Products

Nepxion Discovery