漏洞描述
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache ShardingSphere ElasticJob-UI allows an attacker who has guest account to do privilege escalation. This issue affects Apache ShardingSphere ElasticJob-UI Apache ShardingSphere ElasticJob-UI 3.x version 3.0.0 and prior versions.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
www.vicarius.iohttps://www.vicarius.io/vsociety/blog/cve-2022-22733-apache-shardingsphere-elasticjob-ui-privilege-escalation↗nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2022-22733↗lists.apache.orghttps://lists.apache.org/thread/qpdsm936n9bhksb0rzn6bq1h7ord2nm6↗www.openwall.comhttp://www.openwall.com/lists/oss-security/2022/01/20/2↗github.comhttps://github.com/Zeyad-Azima/CVE-2022-22733↗