vendor:
Equinox
by:
Andrzej Olchawa, Milenko Starcik, VisionSpace Technologies GmbH
6.1
CVSS
HIGH
Remote Code Execution (RCE)
RCE-78
CWE
Product Name: Equinox
Affected Version From: 3.7.2002
Affected Version To: 3.7.2002
Patch Exists: NO
Related CWE: CVE-2023-XXXX (example)
CPE: a:eclipse:equinox:3.7.2
Platforms Tested: Linux
2023
OSGi v3.7.2 Console Remote Code Execution
The exploit allows an attacker to establish a reverse shell connection on systems running OSGi v3.7.2 or earlier.
Mitigation:
Update OSGi to version 3.7.3 or later to patch this vulnerability.