PT-2018-17860 · Myrepos+1 · Myrepos+1

Jakub Wilk

·

Publicado

2018-02-14

·

Atualizado

2024-06-15

·

CVE-2018-7032

CVSS v3.1

7.5

Alta

VetorAV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions myrepos versions through 1.20171231
Description The issue allows a malicious website operator or a Man-in-the-Middle (MitM) attacker to execute arbitrary code. This can be achieved by taking advantage of the fact that webcheckout in myrepos does not sanitize URLs passed to git clone. Demonstrated attacks include an "ext::sh -c" attack or an option injection attack.
Recommendations For versions through 1.20171231, update to a version that sanitizes URLs passed to git clone to prevent arbitrary code execution.

Exploit

Correção

Special Elements Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2018-2065
CVE-2018-7032
OPENSUSE-SU-2024:11063-1

Produtos afetados

Alt Linux
Myrepos