PT-2023-26743 · Oscore · Oscore

Published

2023-07-28

·

Updated

2023-08-03

·

CVE-2023-39022

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions oscore versions 2.2.6 and below
Description The issue is related to a code injection vulnerability in the component com.opensymphony.util.EJBUtils.createStateless(). This vulnerability can be exploited by passing an unchecked argument to the affected component.
Recommendations For oscore versions 2.2.6 and below, consider restricting access to the com.opensymphony.util.EJBUtils.createStateless() function until a patch is available. As a temporary workaround, ensure that all arguments passed to this function are thoroughly checked and validated to prevent potential code injection.

Exploit

Fix

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2023-39022
GHSA-859M-2PFX-FWHF

Affected Products

Oscore