PT-2024-1297 · Mock+1 · Mock+1

Marco Benatto

·

Published

2024-01-16

·

Updated

2024-10-25

·

CVE-2023-6395

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Mock (affected versions not specified)
Description The Mock software contains a vulnerability that could potentially be exploited for privilege escalation, enabling the execution of arbitrary code with root user privileges. This weakness stems from the absence of proper sandboxing during the expansion and execution of Jinja2 templates, which may be included in certain configuration parameters. The issue may allow less privileged users to define configuration tags that could be passed as parameters to mock during execution, potentially leading to the utilization of Jinja2 templates for remote privilege escalation and the execution of arbitrary code as the root user on the build server.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Code Injection

RCE

Weakness Enumeration

Related Identifiers

AZL-43540
BDU:2024-00736
CVE-2023-6395
GHSA-7J98-74JH-CJXH

Affected Products

Mock
Red Os