CVE-2022-31764

CVSS 3.1 Score 8.5 of 10 (high)

Details

Published Feb 6, 2025
CWE ID 913

Summary

CVE-2022-31764 is a remote code execution (RCE) vulnerability affecting the Lite UI of Apache ShardingSphere ElasticJob-UI. An attacker can exploit this issue by constructing a malicious JDBC URL for the H2 database, gaining the ability to execute arbitrary code. This vulnerability is significant as it allows attackers to take control of affected systems, provided they have obtained the account and password. Versions 3.0.1 and prior of ElasticJob-UI are susceptible to this issue, which has been rectified in version 3.0.2.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share