A Improper Control of Generation of Code ('Code Injection') vulnerability in groovy script function in SmartRobot′s Conversational AI Platform before v7.2.0 allows remote authenticated users to perform arbitrary system commands via Groovy code.
References
History

Thu, 26 Dec 2024 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 26 Dec 2024 04:15:00 +0000

Type Values Removed Values Added
Description A Improper Control of Generation of Code ('Code Injection') vulnerability in groovy script function in SmartRobot′s Conversational AI Platform before v7.2.0 allows remote authenticated users to perform arbitrary system commands via Groovy code.
Title Intumit SmartRobot′s Conversational AI Platform - Improper Control of Generation of Code ('Code Injection')
Weaknesses CWE-94
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ZUSO ART

Published: 2024-12-26T04:05:16.468Z

Updated: 2024-12-26T17:39:54.645Z

Reserved: 2024-12-16T08:11:02.700Z

Link: CVE-2024-12652

cve-icon Vulnrichment

Updated: 2024-12-26T17:39:50.217Z

cve-icon NVD

Status : Received

Published: 2024-12-26T04:15:05.660

Modified: 2024-12-26T04:15:05.660

Link: CVE-2024-12652

cve-icon Redhat

No data.