CVE-2022-31764

HIGH

Apache ShardingSphere ElasticJob-UI <3.0.2 - RCE

Title source: llm
STIX 2.1

Description

The Lite UI of Apache ShardingSphere ElasticJob-UI allows an attacker to perform RCE by constructing a special JDBC URL of H2 database. This issue affects Apache ShardingSphere ElasticJob-UI version 3.0.1 and prior versions. This vulnerability has been fixed in ElasticJob-UI 3.0.2. The premise of this attack is that the attacker has obtained the account and password. Otherwise, the attacker cannot perform this attack.

References (1)

Core 1
Core References

Scores

CVSS v3 8.5
EPSS 0.0063
EPSS Percentile 45.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-913
Status published
Products (1)
apache/shardingsphere_elasticjob-ui < 3.0.2
Published Feb 06, 2025
Tracked Since Feb 18, 2026