PT-2018-16203 · Egg · Egg-Scripts

Pontus_Johnson

·

Published

2018-08-24

·

Updated

2023-02-02

·

CVE-2018-3786

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions egg-scripts versions prior to 2.8.1
Description A command injection issue allows arbitrary shell command execution through a maliciously crafted command line argument. This is only exploitable if a malicious argument is provided on the command line. For example, an attacker could use the eggctl start --daemon --stderr command with a malicious stderr argument, such as '/tmp/eggctl stderr.log; touch /tmp/malicious', to execute arbitrary shell commands.
Recommendations Update to version 2.8.1 or later.

Exploit

Fix

Command Injection

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2018-3786
GHSA-C9J3-WQPH-5XX9

Affected Products

Egg-Scripts