CVE-2023-28935
Apache UIMA DUCC: DUCC (EOL) allows RCE
Vexday Risk Score
21Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 8.8EPSS 3.0%KEV nãoPoC —Nuclei —Metasploit —Patch referenciado
Ciclo de vida
30 mar 2023Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Foundation Apache UIMA DUCC.
When using the "Distributed UIMA Cluster Computing" (DUCC) module of Apache UIMA, an authenticated user that has the permissions to modify core entities can cause command execution as the system user that runs the web process.
As the "Distributed UIMA Cluster Computing" module for UIMA is retired, we do not plan to release a fix for this issue.
NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Productos afectados
Apache Software Foundation · Apache UIMA DUCC¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →