CVE-2022-34113: Code Injection
Published Jul 22, 2022
·Updated
An issue in the component /api/plugin/upload of Dataease v1.11.1 allows attackers to execute arbitrary code via a crafted plugin.
Affected Software
2 affected componentsFixes available
maven/io.dataease:dataease-plugin-common<=1.11.1
1.11.2
Dataease DataEase=1.11.1
Event History
Jul 22, 2022
CVE Published
via MITRE·10:17 PM
Data Sourced
via MITRE·10:17 PM
Description
Jul 23, 2022
Advisory Published
12:00 AM
Frequently Asked Questions
1
What is CVE-2022-34113?
CVE-2022-34113 is a vulnerability in Dataease v1.11.1 that allows attackers to execute arbitrary code via a crafted plugin.
2
What is the severity of CVE-2022-34113?
CVE-2022-34113 has a severity rating of 9.8 (Critical).
3
How can I fix CVE-2022-34113?
You can fix CVE-2022-34113 by updating to version 1.11.2 of Dataease.
4
Where can I find more information about CVE-2022-34113?
You can find more information about CVE-2022-34113 on the NIST National Vulnerability Database (NVD) website and the GitHub pages for Dataease.
5
What is the CWE of CVE-2022-34113?
CVE-2022-34113 belongs to CWE category 94 (Code Injection).