PT-2022-15038 · Ghost · Ghost
Dwisiswant0
·
Published
2022-02-01
·
Updated
2024-08-21
·
CVE-2022-21687
CVSS v3.1
6.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
gh-ost versions prior to 1.1.3
Description
The issue is related to an arbitrary file read vulnerability. It requires the attacker to have access to the target host or trick an administrator into executing a malicious gh-ost command, along with network access from the host running gh-ost to the attacker's malicious MySQL server. The
-database parameter does not properly sanitize user input, leading to arbitrary file reads. This is considered a low severity vulnerability.Recommendations
For versions prior to 1.1.3, update to version 1.1.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the
-database parameter to minimize the risk of exploitation.Exploit
Fix
Special Elements Injection
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ghost