CVE-2022-31860
CRITICALopenremote < 1.0.4 - Remote Code Execution via Groovy Rule Injection
Title source: llmDescription
An issue was discovered in OpenRemote through 1.0.4 allows attackers to execute arbitrary code via a crafted Groovy rule.
References (4)
Core 4
Core References
Product x_refsource_misc
https://github.com/openremote/openremote/
Third Party Advisory x_refsource_misc
https://stackoverflow.com/questions/159148/groovy-executing-shell-commands
Third Party Advisory x_refsource_misc
https://stackoverflow.com/questions/66069960/groovy-shell-sandboxing-best-practices
Exploit, Third Party Advisory x_refsource_misc
https://securityblog101.blogspot.com/2022/09/cve-2022-31860.html
Scores
CVSS v3
9.8
EPSS
0.0170
EPSS Percentile
74.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
total
Details
CWE
CWE-94
Status
published
Products (1)
openremote/openremote
< 1.0.4
Published
Sep 06, 2022
Tracked Since
Feb 18, 2026