CVE-2023-37754: Critical severity powerjob vulnerability
Published Jul 28, 2023
·Updated
PowerJob v4.3.3 was discovered to contain a remote command execution (RCE) vulnerability via the instanceId parameter at /instance/detail.
Affected Software
2 affected components
maven/tech.powerjob:powerjob-common<=4.3.3
Powerjob PowerJob=4.3.3
Event History
Jul 28, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Advisory Published
03:30 PM
Frequently Asked Questions
1
What is the severity of CVE-2023-37754?
CVE-2023-37754 has been classified as a critical vulnerability due to its potential for remote command execution.
2
How do I fix CVE-2023-37754?
To fix CVE-2023-37754, upgrade PowerJob to a version higher than 4.3.3 that addresses this vulnerability.
3
What can be exploited in CVE-2023-37754?
CVE-2023-37754 can be exploited through the instanceId parameter at /instance/detail, which allows remote command execution.
4
Which versions of PowerJob are affected by CVE-2023-37754?
PowerJob v4.3.3 is the only version identified as affected by CVE-2023-37754.
5
Who is vulnerable to CVE-2023-37754?
Any user or organization utilizing PowerJob v4.3.3 is vulnerable to CVE-2023-37754.