openEQUELLA authenticated RCE chain(s)
Authenticated deserialization flaws in openEQUELLA can be chained into remote code execution.
A Full Disclosure post by evan describes authenticated deserialization vulnerabilities in openEQUELLA that can be chained to remote code execution. openEQUELLA is an open-source digital repository for educational material and is widely used by Australian universities. The report links to a technical write-up but does not name a CVE or state that exploitation is ongoing.
- Authenticated deserialization can be chained to remote code execution.
- openEQUELLA is an open-source repository for educational material.
- The software is widely used by Australian universities.
- No CVE or active exploitation is stated in the post.
Posted by evan via Fulldisclosure on Sep 26 SUMMARY: an authenticated deserialization vuln in openEQUELLA allows https://blog.evan.lat/posts/openeq/ openequella is an "open source digital repository" for educational material. it is widely used in australian universities...
This source does not provide full text. Read it at seclists.org.