Vulnerabilities > Apache > Brpc > Critical

DATE CVE VULNERABILITY TITLE RISK
2023-05-08 CVE-2023-31039 Improper Input Validation vulnerability in Apache Brpc
Security vulnerability in Apache bRPC <1.5.0 on all platforms allows attackers to execute arbitrary code via ServerOptions::pid_file. An attacker that can influence the ServerOptions pid_file parameter with which the bRPC server is started can execute arbitrary code with the permissions of the bRPC process. Solution: 1.
network
low complexity
apache CWE-20
critical
9.8