8.5
CVSSv3

CVE-2022-31764

CVSSv4: NA | CVSSv3: 8.5 | CVSSv2: NA | VMScore: 950 | EPSS: 0.00114 | KEV: Not Included
Published: 06/02/2025 Updated: 06/02/2025

Vulnerability Summary

Remote Code Execution in Apache ShardingSphere ElasticJob-UI via H2 JDBC URL

The Lite UI of Apache ShardingSphere ElasticJob-UI allows an malicious user to perform RCE by constructing a special JDBC URL of H2 database. This issue affects Apache ShardingSphere ElasticJob-UI version 3.0.1 and prior versions. This vulnerability has been fixed in ElasticJob-UI 3.0.2. The premise of this attack is that the attacker has obtained the account and password. Otherwise, the attacker cannot perform this attack.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache software foundation apache shardingsphere elasticjob-ui