CVE-2024-0195
A vulnerability, which was classified as critical, was found in spider-flow 0.4.3. Affected is the function FunctionService.saveFunction of the file src/main/java/org/spiderflow/controller/FunctionController.java. The manipulation leads to code injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-249510 is the identifier assigned to this vulnerability. Es wurde eine Schwachstelle in spider-flow 0.4.3 gefunden. Sie wurde als kritisch eingestuft. Es betrifft die Funktion FunctionService.saveFunction der Datei src/main/java/org/spiderflow/controller/FunctionController.java. Durch Manipulieren mit unbekannten Daten kann eine code injection-Schwachstelle ausgenutzt werden. Der Angriff kann über das Netzwerk erfolgen. Der Exploit steht zur öffentlichen Verfügung.
- CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 6.3 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L - CVSS v2.0
- 6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P - EPSS
- 19.40% chance of exploitation in the next 30 days, 97th percentile
- Nuclei
- critical · CWE-94
- Published
- 2024-01-02
- Updated
- 2025-06-17
Proof-of-concept exploits (5)
- laoquanshi/puppy/blob/main/spider-flow%20code%20injection%20causes%20rce.md
- Cappricio-Securities/CVE-2024-01951★ · 2024-06-24
- fa-rrel/CVE-2024-0195-SpiderFlow5★ · 2024-08-31
- gh-ost00/CVE-2024-0195-SpiderFlow5★ · 2024-08-31
- hack-with-rohit/CVE-2024-0195-SpiderFlow0★ · 2024-09-07