CVE-2022-41875
CVSS V2 None
CVSS V3 None
Description
A remote code execution (RCE) vulnerability in Optica allows unauthenticated attackers to execute arbitrary code via specially crafted JSON payloads. Specially crafted JSON payloads may lead to RCE (remote code execution) on the attacked system running Optica. The vulnerability was patched in v. 0.10.2, where the call to the function `oj.load` was changed to `oj.safe_load`.
Overview
- CVE ID
- CVE-2022-41875
- Assigner
- security-advisories@github.com
- Vulnerability Status
- Analyzed
- Published Version
- 2022-11-23T19:15:12
- Last Modified Date
- 2022-11-30T16:07:24
Weakness Enumerations
CPE Configuration (Product)
CPE | Vulnerable | Operator | Version Start | Version End |
---|---|---|---|---|
cpe:2.3:a:airbnb:optica:*:*:*:*:*:*:*:* | 1 | OR | 0.10.2 |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2022-41875 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41875 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2022-11-23 20:00:17 | Added to TrackCVE | |||
2022-12-07 18:02:14 | 2022-11-23T19:15Z | 2022-11-23T19:15:12 | CVE Published Date | updated |
2022-12-07 18:02:14 | 2022-11-30T16:07:24 | CVE Modified Date | updated | |
2022-12-07 18:02:14 | Analyzed | Vulnerability Status | updated | |
2022-12-07 18:02:16 | CPE Information | updated |