CVE-2022-46478

CRITICAL

datax-web <2.1.2 - Command Injection

Title source: llm

Description

The RPC interface in datax-web v1.0.0 and v2.0.0 to v2.1.2 contains no permission checks by default which allows attackers to execute arbitrary commands via crafted Hessian serialized data.

Scores

CVSS v3 9.8
EPSS 0.0071
EPSS Percentile 72.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-502
Status published

Affected Products (1)

datax-web_project/datax-web < 2.1.2

Timeline

Published Jan 13, 2023
Tracked Since Feb 18, 2026