
ricardojoserf/emqx-RCE
Releases1
Frequency
Last Release
Stars47
EMQX Dashboard Malicious Plugin leading to RCE
CVE History
| CVE | Published | CVSS v3 | CVSS v2 |
|---|---|---|---|
| 3 LOW | — | ||
In EMQX before 5.8.6, administrators can install arbitrary novel plugins via the Dashboard web interface. NOTE: the Supplier's position is that this is the intended behavior; however, 5.8.6 adds a defense-in-depth feature in which a plugin's acceptability (for later Dashboard installation) is set by the "emqx ctl plugins allow" CLI command. | |||