Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:38435
HistoryDec 12, 2022 - 5:38 a.m.

Remote Code Injection

2022-12-1205:38:33
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
14
code injection
input validation
remote access
environment variables
software vulnerability

0.003 Low

EPSS

Percentile

70.2%

de.codecentric:spring-boot-admin is vulnerable to remote code injection. The vulnerability exists due to improper validation of user inputs, which allows an attacker to inject and execute malicious code on the system when Notifiers and write access to environment variables are enabled via the UI.

0.003 Low

EPSS

Percentile

70.2%