CVE-2022-23330 is a remote code execution (RCE) vulnerability found in jpress v4.2.0, specifically within the HelloWorldAddonController.java component. This flaw allows authenticated attackers to execute arbitrary code on the affected system by uploading a specially crafted JAR package. The vulnerability carries a high severity CVSS score of 8.8, indicating a critical risk. It can be exploited over the network with low attack complexity and no user interaction, potentially leading to complete compromise of confidentiality, integrity, and availability. Currently, there is no evidence of active exploitation, and no public exploit code is available in common repositories like Metasploit or ExploitDB. The vulnerability has received minimal community attention and media coverage, suggesting it is not widely known or discussed.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.2.0CPE matchmatch criteria | cpe:2.3:a:jpress:jpress:4.2.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.