CVE-2023-29412

Severity
9.8CRITICAL
EPSS
6.2%
top 9.17%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 18

Description

CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause remote code execution when manipulating internal methods through Java RMI interface.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Patches

🔴Vulnerability Details

2
GHSA
GHSA-7p8q-cvq9-54g6: A CWE-78: Improper Handling of Case Sensitivity vulnerability exists that could cause remote code execution when manipulating internal methods through2023-04-18
CVEList
CVE-2023-29412: CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause remote code e2023-04-18
CVE-2023-29412 (CRITICAL CVSS 9.8) | CWE-78: Improper Neutralization of | cvebase.io