PT-2023-12841 · Unknown · Vagrant.Js

Published

2023-01-25

·

Updated

2023-08-08

·

CVE-2022-25962

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions vagrant.js versions all
Description The issue arises from improper input sanitization in the boxAdd function, leading to Command Injection. This allows for potential execution of arbitrary commands.
Recommendations For all versions, consider disabling the boxAdd function until a patch is available to prevent Command Injection attacks. Restrict access to the boxAdd function to minimize the risk of exploitation.

Exploit

Fix

OS Command Injection

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2022-25962
GHSA-54JW-JQR9-6CJ9

Affected Products

Vagrant.Js