PT-2018-9518 · Gig Technology Nv · Jumpscale Portal
Vrico315
·
Publicado
2018-09-06
·
Atualizado
2019-03-07
·
CVE-2018-1000666
CVSS v3.1
10
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
GIG Technology NV JumpScale Portal 7 versions before commit 15443122ed2b1cbfd7bdefc048bf106f075becdb
Description
The issue is related to an OS Command Injection vulnerability in the
notifySpaceModification method. This vulnerability can result in improper validation of parameters, leading to command execution. The attack appears to be exploitable via network connectivity and requires minimal authentication privileges, as everyone can register an account.Recommendations
For GIG Technology NV JumpScale Portal 7 versions before commit 15443122ed2b1cbfd7bdefc048bf106f075becdb, update to a version after commit 15443122ed2b1cbfd7bdefc048bf106f075becdb to resolve the issue. As a temporary workaround, consider restricting access to the
notifySpaceModification method until a patch is available.Exploit
Correção
OS Command Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Jumpscale Portal