Impact
The pig-mesh Pig application contains a flaw in the pig-codegen component, specifically in GeneratorServiceImpl.java, that allows an attacker to inject arbitrary code. The vulnerability arises from unsanitized input handling, leading to code injection that can alter application behavior and potentially execute unauthorized commands.
Affected Systems
Systems running pig-mesh Pig version 3.9.2 or earlier that include the pig-codegen module are susceptible. The vulnerability is present in the pig-codegen component’s GeneratorServiceImpl endpoint, which must be reachable for exploitation.
Risk and Exploitability
The CVSS score of 5.3 places the issue in the moderate range. The EPSS score is below 1%, indicating a low probability of exploitation in the wild, but public exploit code is available. The vulnerability can be triggered remotely, and while the description does not specify the exact impact of injected code, the potential to execute arbitrary code elevates concern. The vulnerability is not listed in CISA’s KEV catalog. Organizations should treat it with moderate urgency and consider the potential for broader compromise if exploited.
OpenCVE Enrichment