Lucene search

K
cveApacheCVE-2023-26512
HistoryJul 17, 2023 - 8:15 a.m.

CVE-2023-26512

2023-07-1708:15:09
CWE-502
apache
web.nvd.nist.gov
47
cve-2023-26512
cwe-502
apache eventmesh
rabbitmq-connector plugin
remote code execution
nvd
security
vulnerability
patch
update
fix
master branch
project repo

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.4

Confidence

High

EPSS

0.007

Percentile

80.4%

CWE-502 Deserialization of Untrusted Data at the rabbitmq-connector plugin module in Apache EventMesh (incubating) V1.7.0\V1.8.0 on windows\linux\mac os e.g. platforms allows attackers to send controlled message and

remote code execute via rabbitmq messages. Users can use the code under the master branch in project repo to fix this issue, we will release the new version as soon as possible.

Affected configurations

Nvd
Vulners
Node
applemacosMatch-
OR
linuxlinux_kernelMatch-
OR
microsoftwindowsMatch-
AND
apacheeventmeshRange1.7.01.8.0
VendorProductVersionCPE
applemacos-cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
linuxlinux_kernel-cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
microsoftwindows-cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
apacheeventmesh*cpe:2.3:a:apache:eventmesh:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "Apache EventMesh (incubating) RabbitMQ connector",
    "vendor": "Apache Software Foundation",
    "versions": [
      {
        "lessThanOrEqual": "1.8.0",
        "status": "affected",
        "version": "1.7.0",
        "versionType": "maven"
      }
    ]
  }
]

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.4

Confidence

High

EPSS

0.007

Percentile

80.4%

Related for CVE-2023-26512