PT-2018-16203 · Egg · Egg-Scripts
Pontus_Johnson
·
Published
2018-08-24
·
Updated
2023-02-02
·
CVE-2018-3786
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
egg-scripts versions prior to 2.8.1
Description
A command injection issue allows arbitrary shell command execution through a maliciously crafted command line argument. This is only exploitable if a malicious argument is provided on the command line. For example, an attacker could use the
eggctl start --daemon --stderr command with a malicious stderr argument, such as '/tmp/eggctl stderr.log; touch /tmp/malicious', to execute arbitrary shell commands.Recommendations
Update to version 2.8.1 or later.
Exploit
Fix
Command Injection
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Egg-Scripts