HIGH
whaleal IceFrog Aviator Template Engine deserialization
Published Jun 18, 2023
8.8
HIGHCVSS 3.1
EPSS 1.11%
Description
A vulnerability classified as problematic has been found in whaleal IceFrog 1.1.8. Affected is an unknown function of the component Aviator Template Engine. The manipulation leads to deserialization. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-231804.
Affected products
-
Affected
- 1.1.8
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (7)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-1885 Advisory
- https://github.com/NanKeXXX/selfVuln_poc/blob/main/whaleal%3Aicefrog/icefrog_1.1.8_RCE.md broken-linkexploitBroken Link
- https://github.com/NanKeXXX/selfVuln_poc/blob/main/whaleal:icefrog/icefrog_1.1.8_RCE.md
- https://github.com/advisories/GHSA-rx62-5cw6-x29q Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-3308
- https://vuldb.com/?ctiid.231804 signaturepermissions-requiredPermissions RequiredThird Party AdvisoryVDB Entry
- https://vuldb.com/?id.231804 vdb-entrytechnical-descriptionPermissions RequiredThird Party AdvisoryVDB Entry
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-1885 | Advisory | |
| https://github.com/NanKeXXX/selfVuln_poc/blob/main/whaleal%3Aicefrog/icefrog_1.1.8_RCE.md | broken-linkexploitBroken Link | |
| https://github.com/NanKeXXX/selfVuln_poc/blob/main/whaleal:icefrog/icefrog_1.1.8_RCE.md | ||
| https://github.com/advisories/GHSA-rx62-5cw6-x29q | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2023-3308 | ||
| https://vuldb.com/?ctiid.231804 | signaturepermissions-requiredPermissions RequiredThird Party AdvisoryVDB Entry | |
| https://vuldb.com/?id.231804 | vdb-entrytechnical-descriptionPermissions RequiredThird Party AdvisoryVDB Entry |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Jun 18, 2023
Updated Aug 2, 2024
Reserved Jun 18, 2023
Link CVE-2023-3308
CISA Vulnrichment
Updated Jul 18, 2024
Red Hat
No data
GitHub
Link GHSA-RX62-5CW6-X29Q