PT-2020-2801 · Umount+1 · Umount+1
Published
2020-04-02
·
Updated
2022-04-22
·
CVE-2020-7628
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
umount versions 1.1.0 through 1.1.6
install-package versions 1.1.0 through 1.1.6
Description
The issue is related to Command Injection. The
device argument can be controlled by users without sanitization, allowing the execution of arbitrary commands via the device function. This may enable remote attackers to execute arbitrary code in the system if the device value passed to the function is user-controlled.Recommendations
For umount versions 1.1.0 through 1.1.6, consider using an alternative package until a fix is made available.
For install-package versions 1.1.0 through 1.1.6, consider using an alternative package until a fix is made available.
As a temporary workaround, consider restricting the use of the
device function in the umount module to minimize the risk of exploitation.Fix
XSS
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Package Installer
Umount