PT-2023-3706 · Acme.Sh · Acme.Sh
Mholt
·
Published
2023-06-09
·
Updated
2024-10-30
·
CVE-2023-38198
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
acme.sh versions prior to 3.0.6
Description
The issue arises from insufficient input validation in the Eval function of the ACME protocol client Acme.sh, allowing a remote attacker to execute arbitrary code. This has been exploited in the wild in June 2023.
Recommendations
For versions prior to 3.0.6, update to version 3.0.6 or later to resolve the issue. As a temporary workaround, consider disabling the use of the
eval function in Acme.sh until a patch is applied. Restrict access to the Acme.sh client to minimize the risk of exploitation. Avoid using the Acme.sh client with untrusted input until the issue is resolved.Fix
RCE
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Acme.Sh