First published: Thu Feb 06 2025(Updated: )
The Lite UI of Apache ShardingSphere ElasticJob-UI allows an attacker to perform RCE by constructing a special JDBC URL of H2 database. This issue affects Apache ShardingSphere ElasticJob-UI version 3.0.1 and prior versions. This vulnerability has been fixed in ElasticJob-UI 3.0.2. The premise of this attack is that the attacker has obtained the account and password. Otherwise, the attacker cannot perform this attack.
Affected Software | Affected Version | How to fix |
---|---|---|
Apache ShardingSphere ElasticJob-UI | <3.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-31764 is classified as a critical vulnerability due to its potential for remote code execution.
To fix CVE-2022-31764, upgrade to Apache ShardingSphere ElasticJob-UI version 3.0.2 or later.
CVE-2022-31764 affects Apache ShardingSphere ElasticJob-UI versions 3.0.1 and earlier.
CVE-2022-31764 enables an attacker to perform remote code execution through a specially crafted JDBC URL.
If upgrading is not possible, mitigating the risk requires limiting access to the application and monitoring for unusual behavior.