RMI was not requiring authentication when calling...
Moderate severity
Unreviewed
Published
Nov 2, 2023
to the GitHub Advisory Database
•
Updated Jan 21, 2024
Description
Published by the National Vulnerability Database
Nov 2, 2023
Published to the GitHub Advisory Database
Nov 2, 2023
Last updated
Jan 21, 2024
RMI was not requiring authentication when calling ChronosRMIService:setEventOrganizer. Attackers with local or adjacent network access could abuse the RMI service to modify calendar items using RMI. RMI access is restricted to localhost by default. The interface has been updated to require authenticated requests. No publicly available exploits are known.
References