8.8
CVSSv3

CVE-2020-17532

Published: 25/01/2021 Updated: 29/01/2021
CVSS v2 Base Score: 6 | Impact Score: 6.4 | Exploitability Score: 6.8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 534
Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P

Vulnerability Summary

When handler-router component is enabled in servicecomb-java-chassis, authenticated user may inject some data and cause arbitrary code execution. The problem happens in versions between 2.0.0 ~ 2.1.3 and fixed in Apache ServiceComb-Java-Chassis 2.1.5

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache java chassis

Mailing Lists

Description: When handler-router component is enabled in servicecomb-java-chassis, authenticated user may inject some data and cause arbitrary code execution The problem happens in versions between 200 ~ 213 and fixed in 215 This issue is being tracked as SCB-2145 ...