PT-2023-31594 · Unknown · Easy-Rules-Mvel

Sirnple

·

Published

2023-12-29

·

Updated

2024-01-05

·

CVE-2023-50571

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions easy-rules-mvel version 4.1.0
Description The issue is related to a remote code execution (RCE) vulnerability via the component MVELRule. This allows for potential exploitation, but specific details about the estimated number of affected devices or real-world incidents are not provided.
Recommendations For easy-rules-mvel version 4.1.0, consider disabling the mVELRule component as a temporary workaround until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Related Identifiers

CVE-2023-50571
GHSA-FGWC-3J6W-CH22

Affected Products

Easy-Rules-Mvel