CVE-2022-25894
published 2023-01-26CVE-2022-25894: All versions of the package com.bstek.uflo:uflo-core are vulnerable to Remote Code Execution (RCE) in the ExpressionContextImpl class via…
PriorityP260critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
2.57%
83.2th percentile
All versions of the package com.bstek.uflo:uflo-core are vulnerable to Remote Code Execution (RCE) in the ExpressionContextImpl class via jexl.createExpression(expression).evaluate(context); functionality, due to improper user input validation.
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Remote Code Execution in com.bstek.uflo:uflo-core
osv·2023-01-26
CVE-2022-25894 [CRITICAL] Remote Code Execution in com.bstek.uflo:uflo-core
Remote Code Execution in com.bstek.uflo:uflo-core
All versions of the package com.bstek.uflo:uflo-core are vulnerable to Remote Code Execution (RCE) in the ExpressionContextImpl class via jexl.createExpression(expression).evaluate(context); functionality, due to improper user input validation.
GHSA
Remote Code Execution in com.bstek.uflo:uflo-core
ghsa·2023-01-26
CVE-2022-25894 [CRITICAL] CWE-94 Remote Code Execution in com.bstek.uflo:uflo-core
Remote Code Execution in com.bstek.uflo:uflo-core
All versions of the package com.bstek.uflo:uflo-core are vulnerable to Remote Code Execution (RCE) in the ExpressionContextImpl class via jexl.createExpression(expression).evaluate(context); functionality, due to improper user input validation.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://fmyyy1.github.io/2022/10/23/uflo2rce/https://github.com/youseries/uflo/blob/b3e198bc6523e5a6ba69edd84ba10e05a3b78726/uflo-core/src/main/java/com/bstek/uflo/expr/impl/ExpressionContextImpl.java%23L126https://security.snyk.io/vuln/SNYK-JAVA-COMBSTEKUFLO-3091112https://fmyyy1.github.io/2022/10/23/uflo2rce/https://github.com/youseries/uflo/blob/b3e198bc6523e5a6ba69edd84ba10e05a3b78726/uflo-core/src/main/java/com/bstek/uflo/expr/impl/ExpressionContextImpl.java%23L126https://security.snyk.io/vuln/SNYK-JAVA-COMBSTEKUFLO-3091112
2023-01-26
Published