PT-2022-17110 · P4 · P4

Published

2022-12-20

·

Updated

2023-08-08

·

CVE-2022-25171

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions p4 versions prior to 0.0.7
Description The issue is related to Command Injection via the run() function due to improper input sanitization.
Recommendations For versions prior to 0.0.7, update to version 0.0.7 or later to resolve the issue. As a temporary workaround, consider disabling the run() function until a patch is available. Restrict access to the run() function to minimize the risk of exploitation.

Exploit

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2022-25171
GHSA-JFM8-HWHG-R6GG

Affected Products

P4