PT-2018-17824 · Centos+2 · Centos+2

Grolinet

+1

·

Publicado

2018-02-12

·

Atualizado

2018-03-16

·

CVE-2018-6926

CVSS v2.0

9.0

Alta

VetorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions MISP version 2.4.87
Description A server setting in MISP permitted the override of a path variable on certain Red Hat Enterprise Linux and CentOS systems, allowing site administrators to inject arbitrary OS commands. The impact is limited as the setting is only accessible to site administrators.
Recommendations For MISP version 2.4.87, consider restricting access to the server setting to prevent arbitrary OS command injection until a patch is available. As a temporary workaround, site administrators should avoid using the vulnerable setting to override path variables on Red Hat Enterprise Linux and CentOS systems where rh shell fix is enabled.

Correção

OS Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-6926

Produtos afetados

Centos
Misp
Red Hat