CVE-2023-52291

CWE-77Command Injection4 documents4 sources
Severity
4.7MEDIUM
EPSS
0.4%
top 39.43%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 17

Description

In streampark, the project module integrates Maven's compilation capabilities. The input parameter validation is not strict, allowing attackers to insert commands for remote command execution, The prerequisite for a successful attack is that the user needs to log in to the streampark system and have system-level permissions. Generally, only users of that system have the authorization to log in, and users would not manually input a dangerous operation command. Therefore, the risk level of this vu

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:LExploitability: 1.2 | Impact: 3.4

Affected Packages3 packages

🔴Vulnerability Details

3
GHSA
Apache StreamPark: Unchecked maven build params could trigger remote command execution2024-07-17
OSV
Apache StreamPark: Unchecked maven build params could trigger remote command execution2024-07-17
CVEList
Apache StreamPark (incubating): Unchecked maven build params could trigger remote command execution2024-07-17
CVE-2023-52291 (MEDIUM CVSS 4.7) | In streampark | cvebase.io