PT-2022-24838 · Mist · Mist

Highhwittenborn

·

Published

2022-09-26

·

Updated

2023-07-13

·

CVE-2022-39245

CVSS v3.1

8.4

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Mist versions prior to 0.9.5
Description Mist is the command-line interface for the makedeb Package Repository. A user-provided sudo binary via the PATH variable can allow a local user to run arbitrary commands on the user's system with root permissions.
Recommendations For versions prior to 0.9.5, update to version 0.9.5 or later to resolve the issue. As a temporary workaround, consider restricting the use of the sudo binary via the PATH variable to minimize the risk of exploitation.

Exploit

Fix

Untrusted Search Path

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2022-39245
GHSA-PXG4-7C7R-2WW6

Affected Products

Mist