PT-2023-32909 · Unknown · Shifuml Shifu

W3Bspl01T3R

·

Published

2023-12-28

·

Updated

2024-05-17

·

CVE-2023-7148

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ShifuML shifu version 0.12.0
Description A critical vulnerability has been found in the Java Expression Language Handler component, specifically in the file src/main/java/ml/shifu/shifu/core/DataPurifier.java. The manipulation of the FilterExpression argument leads to code injection. The attack can be launched remotely, with a rather high complexity and difficult exploitation. The exploit has been disclosed to the public and may be used.
Recommendations For ShifuML shifu version 0.12.0, as a temporary workaround, consider restricting access to the DataPurifier.java file and the Java Expression Language Handler component to minimize the risk of exploitation. Avoid using the FilterExpression argument in the affected functionality until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2023-7148
GHSA-5FPQ-3C9P-3R3W

Affected Products

Shifuml Shifu