Description
In EMQX before 5.8.6, administrators can install arbitrary novel plugins via the Dashboard web interface. NOTE: the Supplier's position is that this is the intended behavior; however, 5.8.6 adds a defense-in-depth feature in which a plugin's acceptability (for later Dashboard installation) is set by the "emqx ctl plugins allow" CLI command.
Problem types
CWE-754 Improper Check for Unusual or Exceptional Conditions
Product status
Any version before 5.8.6
References
github.com/ricardojoserf/emqx-RCE
docs.emqx.com/en/emqx/latest/dashboard/introduction.html
docs.emqx.com/en/emqx/latest/deploy/install-docker.html