Severity
High
Analysis Summary
CVE-2022-22733
Apache ShardingSphere ElasticJob-UI could allow a remote authenticated attacker to gain elevated privileges on the system, caused by a password disclosure flaw in the Access-Token. By sending a specially-crafted request, an authenticated attacker could exploit this vulnerability to gain elevated privileges.
Impact
- Privilege Escalation
Affected Vendors
Apache
Affected Products
- Apache ShardingSphere ElasticJob-UI 3.0.0
Remediation
Upgrade to the latest version of Apache ShardingSphere ElasticJob-UI, available from the shardingsphere-elasticjob-ui GIT Repository.