Skyscreamer Open Source Nevado JMS v1.3.2 does not perform security checks when receiving messages. This allows attackers to execute arbitrary commands via supplying crafted data.
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Link | Tags |
---|---|
http://nevado.skyscreamer.org/ | product |
https://github.com/skyscreamer/nevado/releases | release notes |
https://novysodope.github.io/2023/04/01/95/ | third party advisory exploit |
https://github.com/skyscreamer/nevado/issues/121 | issue tracking |