PT-2022-28082 · Dropbox · Dropbox
Published
2022-12-27
·
Updated
2024-05-17
·
CVE-2022-4768
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Dropbox merou (affected versions not specified)
Description
A critical issue was found in the SSH Public Key Handler component, specifically in the
add public key function of the grouper/public key.py file. The manipulation of the public key str argument leads to injection. This issue can be exploited remotely.Recommendations
To fix this issue, it is recommended to apply the patch d93087973afa26bc0a2d0a5eb5c0fde748bdd107. As a temporary workaround, consider disabling the
add public key function until the patch is applied. Restrict access to the SSH Public Key Handler component to minimize the risk of exploitation. Avoid using the public key str argument in the affected function until the issue is resolved.Fix
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dropbox