PT-2021-15474 · Picotts · Picotts
Omnitaint
·
Published
2021-04-18
·
Updated
2021-05-07
·
CVE-2021-23378
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
picotts versions prior to 0.1.1
Description
The issue arises when attacker-controlled user input is given to the
say function, allowing an attacker to execute arbitrary commands due to the use of the child process exec function without input sanitization.Recommendations
For versions prior to 0.1.1, as a temporary workaround, consider disabling the
say function until a patch is available. Restrict access to the child process exec function to minimize the risk of exploitation. Avoid using the say function with untrusted input until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Command Injection
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Picotts