one-java-agent是提供插件化支持,统一管理众多的Java Agent。 com.alibaba.oneagent:one-java-agent-plugin 所有版本存在安全漏洞,攻击者利用该漏洞可以覆盖可执行文件并远程调用它们,或者等待系统或用户调用它们,从而在受害者的机器上实现远程命令执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | com.alibaba.oneagent:one-java-agent-plugin | 0 ~ unspecified | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | None | https://github.com/shoucheng3/alibaba__one-java-agent_CVE-2022-25842_0-0-1 | POC Details |
No public POC found.
Login to generate AI POC| CVE-2022-24437 | 9.8 CRITICAL | Command Injection |
| CVE-2022-25767 | 9.8 CRITICAL | Remote Code Execution |
| CVE-2022-23923 | 8.6 HIGH | Sandbox Bypass |
| CVE-2022-25301 | 7.7 HIGH | Prototype Pollution |
| CVE-2022-25647 | 7.7 HIGH | Deserialization of Untrusted Data |
| CVE-2022-21144 | 7.5 HIGH | Denial of Service (DoS) |
| CVE-2022-21227 | 7.5 HIGH | Denial of Service (DoS) |
| CVE-2022-21167 | 7.5 HIGH | Arbitrary Code Execution |
| CVE-2022-22143 | 7.5 HIGH | Prototype Pollution |
| CVE-2022-25850 | 7.5 HIGH | Server-side Request Forgery (SSRF) |
| CVE-2022-21189 | 7.3 HIGH | Prototype Pollution |
| CVE-2022-25645 | 6.5 MEDIUM | Prototype Pollution |
| CVE-2022-26068 | 6.5 MEDIUM | Path Traversal |
| CVE-2022-21230 | 5.5 MEDIUM | Information Exposure |
| CVE-2022-21149 | 5.4 MEDIUM | Cross-site Scripting (XSS) |
| CVE-2022-25349 | 5.4 MEDIUM | Cross-site Scripting (XSS) |
| CVE-2022-25844 | 5.3 MEDIUM | Regular Expression Denial of Service (ReDoS) |
| CVE-2022-29849 | Progress OpenEdge权限许可和访问控制问题漏洞 | |
| CVE-2022-28481 | CSV-Safe gem 安全漏洞 | |
| CVE-2021-31674 | Cyclos 4 PRO 跨站脚本漏洞 |
Showing top 20 of 24 CVEs. View all on vendor page → →
No comments yet