PT-2018-9518 · Gig Technology Nv · Jumpscale Portal

Vrico315

·

Publicado

2018-09-06

·

Atualizado

2019-03-07

·

CVE-2018-1000666

CVSS v3.1

10

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GIG Technology NV JumpScale Portal 7 versions before commit 15443122ed2b1cbfd7bdefc048bf106f075becdb
Description The issue is related to an OS Command Injection vulnerability in the notifySpaceModification method. This vulnerability can result in improper validation of parameters, leading to command execution. The attack appears to be exploitable via network connectivity and requires minimal authentication privileges, as everyone can register an account.
Recommendations For GIG Technology NV JumpScale Portal 7 versions before commit 15443122ed2b1cbfd7bdefc048bf106f075becdb, update to a version after commit 15443122ed2b1cbfd7bdefc048bf106f075becdb to resolve the issue. As a temporary workaround, consider restricting access to the notifySpaceModification method until a patch is available.

Exploit

Correção

OS Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-1000666

Produtos afetados

Jumpscale Portal