CVE-2022-31860: Code Injection
Published Sep 6, 2022
·Updated
An issue was discovered in OpenRemote through 1.0.4 allows attackers to execute arbitrary code via a crafted Groovy rule.
Affected Software
1 affected component
OpenRemote OpenRemote<=1.0.4
Event History
Sep 6, 2022
CVE Published
via MITRE·05:50 PM
Data Sourced
via MITRE·05:50 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-31860?
CVE-2022-31860 is classified as high severity due to its potential to allow arbitrary code execution.
2
How do I fix CVE-2022-31860?
To fix CVE-2022-31860, upgrade OpenRemote to version 1.0.5 or later, which addresses this vulnerability.
3
What systems are affected by CVE-2022-31860?
CVE-2022-31860 affects OpenRemote versions up to and including 1.0.4.
4
What kind of attacks can exploit CVE-2022-31860?
Attackers can exploit CVE-2022-31860 to execute arbitrary code by injecting malicious Groovy rules.
5
Is there a known exploit for CVE-2022-31860?
Yes, there are reports that demonstrate how to exploit CVE-2022-31860 to execute unauthorized commands.