You are viewing a plain text version of this content. The canonical link for it is here.
Posted to announce@apache.org by Haoran Meng <me...@apache.org> on 2022/01/20 06:07:48 UTC
CVE-2022-22733: Apache ShardingSphere ElasticJob-UI: Access-Token in ElasticJob UI causes password disclosure
Severity: moderate
Description:
Exposure of Sensitive Information to an Unauthorized Actor
vulnerability in Apache ShardingSphere ElasticJob-UI allows an
attacker who has guest account to do privilege escalation. This issue
affects Apache ShardingSphere ElasticJob-UI Apache ShardingSphere
ElasticJob-UI 3.x version 3.0.0 and prior versions.
--
Best,
Haoran Meng
Apache ShardingSphere