PT-2020-9130 · Unknown · Devcert-Sanscache
Published
2020-01-08
·
Updated
2020-04-14
·
CVE-2019-10778
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
devcert-sanscache versions prior to 0.4.7
Description
The issue allows remote attackers to execute arbitrary code or cause a Command Injection via the
exec function. The variable commonName, which is controlled by user input, is used as part of the exec function without any sanitization.Recommendations
For devcert-sanscache versions prior to 0.4.7, update to version 0.4.7 or later to resolve the issue. As a temporary workaround, consider disabling the use of the
exec function with user-controlled input until a patch is available. Restrict access to the commonName variable to minimize the risk of exploitation.Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Devcert-Sanscache