PT-2017-17560 · Deluge+2 · Deluge+2

Jonatan Nyberg

·

Publicado

2017-03-18

·

Atualizado

2020-07-08

·

CVE-2017-7178

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Deluge versions prior to 1.3.14
Description A CSRF issue was found in the web UI of Deluge. The exploitation involves hosting a crafted plugin that executes an arbitrary program from its init .py file and causing the victim to download, install, and enable this plugin.
Recommendations For Deluge versions prior to 1.3.14, update to version 1.3.14 or later to resolve the issue. As a temporary workaround, consider restricting access to the plugin installation feature to minimize the risk of exploitation. Avoid installing plugins from untrusted sources until the issue is resolved.

Exploit

Correção

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2017-2355
CVE-2017-7178
DLA-863-1
DSA-3856-1
OPENSUSE-SU-2017_1497-1

Produtos afetados

Alt Linux
Deluge
Suse