PT-2020-7577 · Unknown · Hubot Scripts

Neal Poole

·

Published

2020-02-12

·

Updated

2020-08-31

·

CVE-2013-7378

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Hubot Scripts versions prior to 2.4.4
Description The issue allows remote attackers to execute arbitrary commands due to a command injection vulnerability in the hubot-scripts/package/src/scripts/email.coffee module. The email script is not enabled by default and must be manually added to hubot's list of loaded scripts.
Recommendations Update hubot-scripts to version 2.4.4 or later.

Fix

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-7378
GHSA-HWCH-749C-RV63

Affected Products

Hubot Scripts