CVE-2019-15631

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
02/12/2019
Last modified:
13/12/2019

Description

Remote Code Execution vulnerability in MuleSoft Mule CE/EE 3.x and API Gateway 2.x released before October 31, 2019 allows remote attackers to execute arbitrary code.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mulesoft:api_gateway:*:*:*:*:*:*:*:* 2.0.0 (including) 2.2.12 (including)
cpe:2.3:a:mulesoft:mule_runtime:*:*:*:*:*:*:community:* 3.0.0 (including) 3.9.3 (including)
cpe:2.3:a:mulesoft:mule_runtime:*:*:*:*:*:enterprise:*:* 3.0.0 (including) 3.9.3 (including)