CVE-2023-54344: Eclipse Equinox OSGi 3.7.2 Remote Code Execution via Console
Eclipse Equinox OSGi 3.7.2 and earlier contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary commands by sending payloads to the console interface. Attackers can connect to the OSGi console port and send base64-encoded bash commands wrapped in fork directives to achieve code execution and establish reverse shell connections.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-54344?
CVE-2023-54344 is classified as a critical vulnerability due to its potential for remote code execution by unauthenticated attackers.
How do I fix CVE-2023-54344?
To mitigate CVE-2023-54344, upgrade Eclipse Equinox OSGi to version 3.8.0 or later, which addresses this vulnerability.
What are the potential impacts of CVE-2023-54344?
The impact of CVE-2023-54344 includes the ability for attackers to execute arbitrary commands on the affected system, leading to potential data breaches or system compromise.
Who is affected by CVE-2023-54344?
CVE-2023-54344 affects all versions of Eclipse Equinox OSGi up to and including 3.7.2.
Is authentication required to exploit CVE-2023-54344?
No, CVE-2023-54344 can be exploited by unauthenticated attackers without any prior access.