Apache bRPC Vulnerability Enables Remote Command Injection

A critical remote command-injection vulnerability has been discovered in Apache bRPC’s built-in heap profiler service, affecting all versions before 1.15.0 across all platforms. The vulnerability allows unauthenticated attackers to execute arbitrary system commands by manipulating the profiler’s parameter validation mechanisms. The heap profiler service endpoint (/pprof/heap) fails to properly sanitize the extra_options parameter before passing it to […]

The post Apache bRPC Vulnerability Enables Remote Command Injection appeared first on Cyber Security News.

This article has been indexed from Cyber Security News

Read the original article: