Description
When handler-router component is enabled in servicecomb-java-chassis, authenticated user may inject some data and cause arbitrary code execution. The problem happens in versions between 2.0.0 ~ 2.1.3 and fixed in Apache ServiceComb-Java-Chassis 2.1.5
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No solution or workaround provided in the CVE record.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-1140 | When handler-router component is enabled in servicecomb-java-chassis, authenticated user may inject some data and cause arbitrary code execution. The problem happens in versions between 2.0.0 ~ 2.1.3 and fixed in Apache ServiceComb-Java-Chassis 2.1.5 |
Github GHSA |
GHSA-px4w-rcv2-6x8x | Arbitrary code execution in Apache ServiceComb java-chassis |
References
History
No history.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2025-02-13T16:27:38.219Z
Reserved: 2020-08-12T00:00:00.000Z
Link: CVE-2020-17532
No data.
Status : Modified
Published: 2021-01-25T10:16:32.533
Modified: 2026-06-17T02:59:05.963
Link: CVE-2020-17532
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA