Description
The RPC interface in datax-web v1.0.0 and v2.0.0 to v2.1.2 contains no permission checks by default which allows attackers to execute arbitrary commands via crafted Hessian serialized data.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-49282 | The RPC interface in datax-web v1.0.0 and v2.0.0 to v2.1.2 contains no permission checks by default which allows attackers to execute arbitrary commands via crafted Hessian serialized data. |
References
| Link | Providers |
|---|---|
| https://github.com/WeiYe-Jing/datax-web/issues/587 |
|
History
Mon, 07 Apr 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-04-07T19:04:03.335Z
Reserved: 2022-12-05T00:00:00.000Z
Link: CVE-2022-46478
Updated: 2024-08-03T14:31:46.361Z
Status : Modified
Published: 2023-01-13T01:15:10.090
Modified: 2025-04-07T19:15:44.780
Link: CVE-2022-46478
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD