CVE-2022-4322
Published on: Not Yet Published
Last Modified on: 12/09/2022 12:59:00 AM UTC
Certain versions of Maku-boot from Maku contain the following vulnerability:
A vulnerability, which was classified as critical, was found in maku-boot up to 2.2.0. This affects the function doExecute of the file AbstractScheduleJob.java of the component Scheduled Task Handler. The manipulation leads to injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The name of the patch is 446eb7294332efca2bfd791bc37281cedac0d0ff. It is recommended to apply a patch to fix this issue. The identifier VDB-215013 was assigned to this vulnerability.
- CVE-2022-4322 has been assigned by
[email protected] to track the vulnerability - currently rated as HIGH severity.
CVSS3 Score: 7.2 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | HIGH | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Any sql statement execution vulnerability · Issue #I5ZUYI · MAKU/maku-boot - Gitee.com | gitee.com text/html |
![]() |
CVE-2022-4322 | maku-boot Scheduled Task AbstractScheduleJob.java doExecute injection | vuldb.com text/html |
![]() |
Login - Gitee.com | gitee.com text/html |
![]() |
Exploit/POC from Github
This repository contains a collection of data files on known Common Vulnerabilities and Exposures (CVEs). Each file i…
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Maku | Maku-boot | All | All | All | All |
- cpe:2.3:a:maku:maku-boot:*:*:*:*:*:*:*:*:
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2022-4322 : A vulnerability, which was classified as critical, was found in maku-boot up to 2.2.0. This affects… twitter.com/i/web/status/1… | 2022-12-07 07:07:45 |
![]() |
[Exploit] Updated entry VDB-215013 lists an exploit for CVE-2022-4322 vuldb.com/?id.215013 #exploit #exploits #poc | 2022-12-07 07:36:57 |
![]() |
CVE-2022-4322 | 2022-12-07 07:38:15 |