Eclipse Equinox OSGi versions 3.8 through 3.18 contain a remote code execution vulnerability in the console interface that allows unauthenticated attackers to execute arbitrary code by exploiting the fork command functionality. Attackers can establish a telnet connection to the OSGi console, perform a telnet handshake, and send fork commands to download and execute malicious Java code, establishing a reverse shell connection.
References
Configurations
No configuration.
History
05 May 2026, 12:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-05 12:16
Updated : 2026-05-05 19:47
NVD link : CVE-2023-54342
Mitre link : CVE-2023-54342
CVE.ORG link : CVE-2023-54342
JSON object : View
Products Affected
No product.
CWE
CWE-306
Missing Authentication for Critical Function
