CVE-2022-34558
CRITICALWMAgent v1.3.3rc2-1.3.3rc1 & reqmgr 2 v1.4.0rc2 - RCE
Title source: llmDescription
WMAgent v1.3.3rc2 and 1.3.3rc1, reqmgr 2 1.4.1rc5 and 1.4.0rc2, reqmon 1.4.1rc5, and global-workqueue 1.4.1rc5 allows attackers to execute arbitrary code via a crafted dbs-client package.
References (1)
Core 1
Core References
Exploit, Issue Tracking, Third Party Advisory x_refsource_misc
https://github.com/dmwm/WMCore/issues/11188
Scores
CVSS v3
9.8
EPSS
0.0101
EPSS Percentile
59.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
Status
published
Products (9)
global-workqueue_project/global-workqueue
1.4.1 rc5
pypi/global-workqueue
1.4.1rc5 - 2.0.4PyPI
pypi/reqmgr2
1.4.0rc2 - 2.0.4PyPI
pypi/reqmon
1.4.1rc5 - 2.0.4PyPI
pypi/wmagent
1.3.3rc1 - 2.0.4PyPI
reqmgr2_project/reqmgr2
1.4.0 rc2
reqmgr2_project/reqmgr2
1.4.1 rc5
reqmon_project/reqmon
1.4.1 rc5
wmagent_project/wmagent
1.3.3 rc1 (2 CPE variants)
Published
Jul 28, 2022
Tracked Since
Feb 18, 2026