First published: Tue Sep 06 2022(Updated: )
An issue was discovered in OpenRemote through 1.0.4 allows attackers to execute arbitrary code via a crafted Groovy rule.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Openr Opentmpfiles | <=1.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-31860 is classified as high severity due to its potential to allow arbitrary code execution.
To fix CVE-2022-31860, upgrade OpenRemote to version 1.0.5 or later, which addresses this vulnerability.
CVE-2022-31860 affects OpenRemote versions up to and including 1.0.4.
Attackers can exploit CVE-2022-31860 to execute arbitrary code by injecting malicious Groovy rules.
Yes, there are reports that demonstrate how to exploit CVE-2022-31860 to execute unauthorized commands.