PT-2018-16203 · Egg · Egg-Scripts
Pontus_Johnson
·
Publicado
2018-08-24
·
Atualizado
2023-02-02
·
CVE-2018-3786
CVSS v2.0
10
Crítica
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
egg-scripts versions prior to 2.8.1
Description
A command injection issue allows arbitrary shell command execution through a maliciously crafted command line argument. This is only exploitable if a malicious argument is provided on the command line. For example, an attacker could use the
eggctl start --daemon --stderr command with a malicious stderr argument, such as '/tmp/eggctl stderr.log; touch /tmp/malicious', to execute arbitrary shell commands.Recommendations
Update to version 2.8.1 or later.
Exploit
Correção
Command Injection
OS Command Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Egg-Scripts