First published: Fri Jul 22 2022(Updated: )
An issue in the component /api/plugin/upload of Dataease v1.11.1 allows attackers to execute arbitrary code via a crafted plugin.
Credit: cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
maven/io.dataease:dataease-plugin-common | <=1.11.1 | 1.11.2 |
Dataease | =1.11.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-34113 is a vulnerability in Dataease v1.11.1 that allows attackers to execute arbitrary code via a crafted plugin.
CVE-2022-34113 has a severity rating of 9.8 (Critical).
You can fix CVE-2022-34113 by updating to version 1.11.2 of Dataease.
You can find more information about CVE-2022-34113 on the NIST National Vulnerability Database (NVD) website and the GitHub pages for Dataease.
CVE-2022-34113 belongs to CWE category 94 (Code Injection).