{ "id": "CVE-2022-34267", "sourceIdentifier": "cve@mitre.org", "published": "2023-12-25T08:15:07.200", "lastModified": "2023-12-25T08:15:07.200", "vulnStatus": "Received", "descriptions": [ { "lang": "en", "value": "An issue was discovered in RWS WorldServer before 11.7.3. Adding a token parameter with the value of 02 bypasses all authentication requirements. Arbitrary Java code can be uploaded and executed via a .jar archive to the ws-api/v2/customizations/api endpoint." } ], "metrics": {}, "references": [ { "url": "https://www.rws.com/localization/products/trados-enterprise/worldserver/", "source": "cve@mitre.org" }, { "url": "https://www.triskelelabs.com/vulnerabilities-in-rws-worldserver", "source": "cve@mitre.org" } ] }