Critical severity9.8NVD Advisory· Published Sep 6, 2022· Updated Jun 17, 2026
CVE-2022-31860
CVE-2022-31860
Description
An issue was discovered in OpenRemote through 1.0.4 allows attackers to execute arbitrary code via a crafted Groovy rule.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:openremote:openremote:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:openremote:openremote:*:*:*:*:*:*:*:*range: <=1.0.4
- (no CPE)
- (no CPE)range: <=1.0.4
Patches
Vulnerability mechanics
References
3- securityblog101.blogspot.com/2022/09/cve-2022-31860.htmlnvdExploitThird Party Advisory
- stackoverflow.com/questions/159148/groovy-executing-shell-commandsnvdThird Party Advisory
- stackoverflow.com/questions/66069960/groovy-shell-sandboxing-best-practicesnvdThird Party Advisory
News mentions
0No linked articles in our index yet.