PT-2018-16203 · Egg · Egg-Scripts

Pontus_Johnson

·

Publicado

2018-08-24

·

Atualizado

2023-02-02

·

CVE-2018-3786

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions egg-scripts versions prior to 2.8.1
Description A command injection issue allows arbitrary shell command execution through a maliciously crafted command line argument. This is only exploitable if a malicious argument is provided on the command line. For example, an attacker could use the eggctl start --daemon --stderr command with a malicious stderr argument, such as '/tmp/eggctl stderr.log; touch /tmp/malicious', to execute arbitrary shell commands.
Recommendations Update to version 2.8.1 or later.

Exploit

Correção

Command Injection

OS Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-3786
GHSA-C9J3-WQPH-5XX9

Produtos afetados

Egg-Scripts