VDB

CVE-2020-13151

CVE-2020-13151 PUBLISHED CVSS 10 CRITICAL

Aerospike Community Edition 4.9.0.5 allows for unauthenticated submission and execution of user-defined functions (UDFs), written in Lua, as part of a database query. It attempts to restrict code execution by disabling os.execute() calls, but this is insufficient. Anyone with network access can use a crafted UDF to execute arbitrary OS commands on all nodes of the cluster at the permission level of the user running the Aerospike service.

EPSS 89.95% · 99.6th percentile

Risk Scores

CVSS 2.0
10
EPSS Score
89.95%
99.6th percentile

Affected Products

VendorProductVersions
n/an/a*
aerospikeaerospike_server0, 4.6.0.1, 4.7.0.1

Timeline

  • Aug 5, 2020 CVE Published
  • Nov 17, 2020 PoC Published
  • Dec 10, 2020 PoC Published
  • Dec 11, 2020 PoC Published
  • Apr 14, 2021 EPSS Score
  • Aug 24, 2021 EPSS Score
  • Dec 27, 2021 EPSS Score
  • Feb 28, 2022 EPSS Score
  • Jul 3, 2022 EPSS Score
  • Nov 6, 2022 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Mar 12, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›