Description
When handler-router component is enabled in servicecomb-java-chassis, authenticated user may inject some data and cause arbitrary code execution. The problem happens in versions between 2.0.0 ~ 2.1.3 and fixed in Apache ServiceComb-Java-Chassis 2.1.5
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-1140 | When handler-router component is enabled in servicecomb-java-chassis, authenticated user may inject some data and cause arbitrary code execution. The problem happens in versions between 2.0.0 ~ 2.1.3 and fixed in Apache ServiceComb-Java-Chassis 2.1.5 |
Github GHSA |
GHSA-px4w-rcv2-6x8x | Arbitrary code execution in Apache ServiceComb java-chassis |
References
History
No history.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2025-02-13T16:27:38.219Z
Reserved: 2020-08-12T00:00:00.000Z
Link: CVE-2020-17532
No data.
Status : Modified
Published: 2021-01-25T10:16:32.533
Modified: 2024-11-21T05:08:18.933
Link: CVE-2020-17532
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA