Vulnerability Description
Symmetric DS <3.12.0 uses mx4j to provide access to JMX over HTTP. mx4j, by default, has no auth and is available on all interfaces. An attacker can interact with JMX: get system info, and invoke MBean methods. It is possible to install additional MBeans from a remote host using MLet that leads to arbitrary code execution.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Jumpmind | Symmetricds | < 3.12.0 |
References
- https://www.symmetricds.org/issues/view.php?id=4263Vendor Advisory
- https://www.symmetricds.org/issues/view.php?id=4263Vendor Advisory
FAQ
What is CVE-2020-24231?
CVE-2020-24231 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Symmetric DS <3.12.0 uses mx4j to provide access to JMX over HTTP. mx4j, by default, has no auth and is available on all interfaces. An attacker can interact with JMX: get system info, and invoke MBea...
How severe is CVE-2020-24231?
CVE-2020-24231 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-24231?
Check the references section above for vendor advisories and patch information. Affected products include: Jumpmind Symmetricds.