Impact
The vulnerability is a deserialization of untrusted data flaw that allows attackers to execute arbitrary code on the host running Apache Shindig. An attacker who can send crafted requests to the Shindig REST API can trigger the flaw, resulting in full compromise of the server’s confidentiality, integrity, and availability.
Affected Systems
All releases of Apache Shindig Common and Apache Shindig Social-Api are affected. The project has been retired and no future fixes will be released.
Risk and Exploitability
The vulnerability can be exploited by any authenticated or unauthenticated user with access to the OpenSocial REST API, but the description does not specify additional prerequisites. The EPSS score is not provided, and the vulnerability is not listed in the CISA KEV catalog. Given the lack of a patch and the nature of remote code execution, the risk remains high and attackers can rely on this flaw without restrictions. The CVSS score is 7.2, indicating high severity.
OpenCVE Enrichment