You are viewing a plain text version of this content. The canonical link for it is here.
Posted to announce@apache.org by Haoran Meng <me...@apache.org> on 2022/01/20 06:07:48 UTC

CVE-2022-22733: Apache ShardingSphere ElasticJob-UI: Access-Token in ElasticJob UI causes password disclosure

Severity: moderate

Description:

Exposure of Sensitive Information to an Unauthorized Actor
vulnerability in Apache ShardingSphere ElasticJob-UI allows an
attacker who has guest account to do privilege escalation. This issue
affects Apache ShardingSphere ElasticJob-UI Apache ShardingSphere
ElasticJob-UI 3.x version 3.0.0 and prior versions.


-- 
Best,
Haoran Meng
Apache ShardingSphere