CyberRota Analysis
AI-GeneratedIn AntFlow V2.0.0, the ActivitiTest.java component allows users to execute JUEL expressions without proper input filtering, resulting in a command execution vulnerability. This flaw could enable an attacker to execute arbitrary commands on the server, posing a significant risk to the integrity and availability of the affected Java applications. Organizations using this version of AntFlow should prioritize remediation to mitigate potential exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
In AntFlow V2.0.0, ActivitiTest.java enables users to execute JUEL expressions without filtering the user input, which leads to a command execution vulnerability.