PT-2023-12208 · Unknown · Stoqey Gnuplot

Published

2023-03-10

·

Updated

2023-08-08

·

CVE-2021-33360

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Stoqey gnuplot versions 0.0.3 and earlier
Description An issue in Stoqey gnuplot allows attackers to execute arbitrary code via the src/index.ts, plotCallack, child process, and/or filePath parameters.
Recommendations For Stoqey gnuplot versions 0.0.3 and earlier, consider disabling the child process and restricting access to the filePath parameter until a patch is available. As a temporary workaround, avoid using the plotCallack function in the src/index.ts file to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2021-33360
GHSA-795W-7426-M94J

Affected Products

Stoqey Gnuplot