4
CVSSv2

CVE-2022-22733

Published: 20/01/2022 Updated: 26/01/2022
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache ShardingSphere ElasticJob-UI allows an attacker who has guest account to do privilege escalation. This issue affects Apache ShardingSphere ElasticJob-UI Apache ShardingSphere ElasticJob-UI 3.x version 3.0.0 and prior versions.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache shardingsphere elasticjob-ui 3.0.0

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> oss-sec mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> CVE-2022-22733: Apache ShardingSphere ElasticJob-UI: Access-Token in ElasticJob UI causes password disclosure <!--X-Subject-He ...

Github Repositories

Apache ShardingSphere ElasticJob-UI Privilege Escalation & RCE Exploit

CVE-2022-22733 CVE-2022-22733 is a vulnerabilit that affects Apache ShardingSphere ElasticJob-UI 300 and below versions, The vulnerability lead to Privilege Escalation But, with abusing of the escalated privileges a JDBC Attack it can preformed &amp; achieve RCE You can read the vulnerability analysis from Here &amp; The exploit writing blog step by step from Here