Lucene search

K
nvd[email protected]NVD:CVE-2023-39106
HistoryAug 21, 2023 - 5:15 p.m.

CVE-2023-39106

2023-08-2117:15:48
CWE-502
web.nvd.nist.gov
3
vulnerability
remote code execution
nacos group
nacos spring project
snakeyamls constructor()

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8.9

Confidence

High

EPSS

0.002

Percentile

53.5%

An issue in Nacos Group Nacos Spring Project v.1.1.1 and before allows a remote attacker to execute arbitrary code via the SnakeYamls Constructor() component.

Affected configurations

Nvd
Node
alibabacloudnacos_spring_projectRange1.1.1
VendorProductVersionCPE
alibabacloudnacos_spring_project*cpe:2.3:a:alibabacloud:nacos_spring_project:*:*:*:*:*:*:*:*

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8.9

Confidence

High

EPSS

0.002

Percentile

53.5%

Related for NVD:CVE-2023-39106