CVE-2023-42404

OneVision Workspace before WS23.1 SR1 (build w31.040) allows arbitrary Java EL execution.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:onevision:workspace:22.1:-:*:*:*:*:*:*
cpe:2.3:a:onevision:workspace:22.2:-:*:*:*:*:*:*
cpe:2.3:a:onevision:workspace:23.1:-:*:*:*:*:*:*

History

12 May 2025, 19:36

Type Values Removed Values Added
CPE cpe:2.3:a:onevision:workspace:22.1:-:*:*:*:*:*:*
cpe:2.3:a:onevision:workspace:23.1:-:*:*:*:*:*:*
cpe:2.3:a:onevision:workspace:22.2:-:*:*:*:*:*:*
References () https://code-white.com/public-vulnerability-list/ - () https://code-white.com/public-vulnerability-list/ - Third Party Advisory
References () https://www.onevision.com/ - () https://www.onevision.com/ - Product
First Time Onevision
Onevision workspace

29 Apr 2025, 13:52

Type Values Removed Values Added
Summary
  • (es) OneVision Workspace anterior a WS23.1 SR1 (compilación w31.040) permite la ejecución arbitraria de Java EL.

28 Apr 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-28 17:15

Updated : 2025-05-12 19:36


NVD link : CVE-2023-42404

Mitre link : CVE-2023-42404

CVE.ORG link : CVE-2023-42404


JSON object : View

Products Affected

onevision

  • workspace
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')