漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Apache ShardingSphere ElasticJob-UI allows RCE via event trace data source JDBC
Vulnerability Description
The Lite UI of Apache ShardingSphere ElasticJob-UI allows an attacker to perform RCE by constructing a special JDBC URL of H2 database. This issue affects Apache ShardingSphere ElasticJob-UI version 3.0.1 and prior versions. This vulnerability has been fixed in ElasticJob-UI 3.0.2. The premise of this attack is that the attacker has obtained the account and password. Otherwise, the attacker cannot perform this attack.
CVSS Information
N/A
Vulnerability Type
动态管理代码资源的控制不恰当
Vulnerability Title
Apache ShardingSphere ElasticJob-UI 安全漏洞
Vulnerability Description
Apache ShardingSphere ElasticJob-UI是美国阿帕奇(Apache)基金会的一个 ElasticJob 的管理员控制台。 Apache ShardingSphere ElasticJob-UI 3.0.1版本及之前版本存在安全漏洞。攻击者利用该漏洞可以执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A