Skip to content

There is a code execution vulnerability caused by the upload of a plugin in the src/main/java/com/cool/core/plugin/service/CoolPluginService.java #21

@liyunqiangs

Description

@liyunqiangs

Dynamic JAR loading lacks security verification.

Image

Construct a JAR package containing malicious code.The IP address of the attack machine is 10.252.120.38,and the server address is 10.25.10.140.

Image

Log in to an account with plugin management function remotely.

Image

Malicious plugin was successfully uploaded and initialized for execution.

Image

The attack machine listened to port 8080 and successfully received the request from the server.

Image

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions