Remote Code Execution in Any23
Critical severity
GitHub Reviewed
Published
Sep 13, 2021
to the GitHub Advisory Database
•
Updated Feb 1, 2023
Description
Published by the National Vulnerability Database
Sep 11, 2021
Reviewed
Sep 13, 2021
Published to the GitHub Advisory Database
Sep 13, 2021
Last updated
Feb 1, 2023
A Remote Code Execution (RCE) vulnerability was discovered in the Any23 YAMLExtractor.java file and is known to affect Any23 versions < 2.5. RCE vulnerabilities allow a malicious actor to execute any code of their choice on a remote machine over LAN, WAN, or internet. RCE belongs to the broader class of arbitrary code execution (ACE) vulnerabilities.
References