PT-2022-10316 · Proctree · Proctree

Published

2022-06-01

·

Updated

2022-06-09

·

CVE-2021-34082

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions proctree versions through 0.1.1
Description The issue allows attackers to execute arbitrary commands via the fix function, which is a form of OS Command Injection. This can potentially lead to unauthorized access and execution of system commands.
Recommendations For versions through 0.1.1, consider disabling the fix function until a patch is available to prevent the execution of arbitrary commands.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-34082
GHSA-CV76-RV4H-4MQC

Affected Products

Proctree