PT-2023-15508 · Jedox · Jedox
Published
2023-05-02
·
Updated
2025-01-30
·
CVE-2022-47876
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Jedox versions 2020.2.5
Description
The issue allows remote authenticated users to create jobs that can execute arbitrary code via Groovy scripts. This is related to the integrator component in the affected software.
Recommendations
For version 2020.2.5, consider disabling the Groovy script execution functionality as a temporary workaround until a patch is available. Restrict access to the integrator component to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Jedox