CVE-2022-31764
CVSS 3.1 Score 8.5 of 10 (high)
Details
Published Feb 6, 2025
CWE ID 913
Summary
CVE-2022-31764 is a remote code execution (RCE) vulnerability affecting the Lite UI of Apache ShardingSphere ElasticJob-UI. An attacker can exploit this issue by constructing a malicious JDBC URL for the H2 database, gaining the ability to execute arbitrary code. This vulnerability is significant as it allows attackers to take control of affected systems, provided they have obtained the account and password. Versions 3.0.1 and prior of ElasticJob-UI are susceptible to this issue, which has been rectified in version 3.0.2.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share