PT-2018-9601 · Phkp · Phkp

Wolfgang Hotwagner

·

Publicado

2018-12-20

·

Atualizado

2019-10-03

·

CVE-2018-1000885

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: PHKP version including commit 88fd9cfdf14ea4b6ac3e3967feea7bcaabb6f03b
Description: The issue is related to an improper neutralization of special elements used in a command, which can lead to command injection. This can result in the manipulation of gpg-keys or the execution of commands remotely. The attack is exploitable via the HKP-Api, specifically the endpoint "/pks/lookup?search".
Recommendations: For PHKP version including commit 88fd9cfdf14ea4b6ac3e3967feea7bcaabb6f03b, consider disabling the pgp exec() function in phkp.php as a temporary workaround until a patch is available. Restrict access to the HKP-Api endpoint "/pks/lookup?search" to minimize the risk of exploitation.

Exploit

Correção

OS Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-1000885

Produtos afetados

Phkp