PT-2021-21809 · Unknown · Refined Theme+2
Published
2021-11-30
·
Updated
2021-12-01
·
CVE-2021-3769
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
pygmalion theme (affected versions not specified)
pygmalion-virtualenv theme (affected versions not specified)
refined theme (affected versions not specified)
Description
The vulnerability exists in the pygmalion, pygmalion-virtualenv, and refined themes. These themes use
print -P on user-supplied strings to print them to the terminal, specifically on git information such as the branch name. If the branch has a specially-crafted name, the vulnerability can be exploited.Recommendations
For the pygmalion theme, consider disabling the use of
print -P on user-supplied strings until a patch is available.
For the pygmalion-virtualenv theme, consider disabling the use of print -P on user-supplied strings until a patch is available.
For the refined theme, consider disabling the use of print -P on user-supplied strings until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pygmalion Theme
Pygmalion-Virtualenv Theme
Refined Theme