Missing Authorization, Improper Control of Generation of Code ('Code Injection'), Improper Control of Dynamically-Managed Code Resources, Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache Nutch Server (Nutch REST API). Эта проблема затрагивает Apache Nutch: с 1.11 по 1.22. Пользователям рекомендуется выполнить обновление до версии 1.23, которая удаляет сервер Nutch.
Если обновление невозможно, пользователь должен разрешить доступ к экземплярам, на которых запущена служба Nutch, только доверенным пользователям. Пожалуйста, также посетите рекомендации по безопасности Apache Nutch https://nutch.apache.org/documentation/security/.
Показать оригинальное описание (EN)
Missing Authorization, Improper Control of Generation of Code ('Code Injection'), Improper Control of Dynamically-Managed Code Resources, Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache Nutch Server (Nutch REST API). This issue affects Apache Nutch: from 1.11 through 1.22. Users are recommended to upgrade to version 1.23, which removes the Nutch Server. If an upgrade is not possible, user must restrict access to instances running the Nutch Service to trusted users only. Please, also visit the Apache Nutch security advisories https://nutch.apache.org/documentation/security/ .
Характеристики атаки
Последствия
Строка CVSS v3.1
Тип уязвимости (CWE)
Уязвимые продукты 1
| Конфигурация | От (включительно) | До (исключительно) |
|---|---|---|
|
Apache Nutch
cpe:2.3:a:apache:nutch:*:*:*:*:*:*:*:*
|
1.11
|
1.23
|