← volver
CVE-2023-26512criticalCWE-502

Apache EventMesh RabbitMQ-Connector plugin allows RCE through deserialization of untrusted data

28Vexday Risk Score

Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.

ssvc Trackcvss 9.8epss 1.4%
probabilidad de explotación
1.4%top 28% de las CVE
explotación observada
noninguna fuente lo reporta
CWE-502 Deserialization of Untrusted Data at the rabbitmq-connector plugin module in Apache EventMesh (incubating) V1.7.0\V1.8.0 on windows\linux\mac os e.g. platforms allows attackers to send controlled message and remote code execute via rabbitmq messages. Users can use the code under the master branch in project repo to fix this issue, we will release the new version as soon as possible.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H