Informazioni sul CVE-2022-33980
Apache Commons Configuration insecure interpolation defaults
CWE ID: N/A
Base Score (CVSS): N/A
CVE: CVE-2022-33980
Descrizione: Apache Commons Configuration performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolation is “${prefix:name}”, where “prefix” is used to locate an instance of org.apache.commons.configuration2.interpol.Lookup that performs the interpolation. Starting with version 2.4 and continuing through 2.7, the set of default Lookup instances included interpolators that could result in arbitrary code execution or contact with remote servers. These lookups are: – “script” – execute expressions using the JVM script execution engine (javax.script) – “dns” – resolve dns records – “url” – load values from urls, including from remote servers Applications using the interpolation defaults in the affected versions may be vulnerable to remote code execution or unintentional contact with remote servers if untrusted configuration values are used. Users are recommended to upgrade to Apache Commons Configuration 2.8.0, which disables the problematic interpolators by default.
Vettore di attacco
Punteggio CVSS
Il CVSS è un sistema di valutazione che misura la gravità di una vulnerabilità informatica considerando fattori come l’impatto potenziale, la probabilità di attacco e la facilità di esecuzione.
Riassunto: .
Dettaglio del Vettore
Metrica | Valore | Significato | Descrizione |
---|
Riferimenti esterni
- https://lists.apache.org/thread/tdf5n7j80lfxdhs2764vn0xmpfodm87s
- http://www.openwall.com/lists/oss-security/2022/07/06/5
- https://security.netapp.com/advisory/ntap-20221028-0015/
- http://www.openwall.com/lists/oss-security/2022/11/15/4
- https://www.debian.org/security/2022/dsa-5290
Prodotti interessati
- Apache Software Foundation – Apache Commons Configuration
Relazioni con altri prodotti
Produttore:Apache Software Foundation
Prodotto: Apache Commons Configuration
Anno: 2022
CWE:
CVSS: 0.0