Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-38h3-jcwf-hx88

Опубликовано: 09 фев. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

External Control of Critical State Data, Improper Control of Generation of Code ('Code Injection') vulnerability in YugaByte, Inc. Yugabyte DB on Windows, Linux, MacOS, iOS (DevopsBase.Java:execCommand, TableManager.Java:runCommand modules) allows API Manipulation, Privilege Abuse. This vulnerability is associated with program files backup.Py. This issue affects Yugabyte DB: Lesser then 2.2.

External Control of Critical State Data, Improper Control of Generation of Code ('Code Injection') vulnerability in YugaByte, Inc. Yugabyte DB on Windows, Linux, MacOS, iOS (DevopsBase.Java:execCommand, TableManager.Java:runCommand modules) allows API Manipulation, Privilege Abuse. This vulnerability is associated with program files backup.Py. This issue affects Yugabyte DB: Lesser then 2.2.

EPSS

Процентиль: 28%
0.001
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-642

Связанные уязвимости

CVSS3: 7.2
nvd
почти 3 года назад

External Control of Critical State Data, Improper Control of Generation of Code ('Code Injection') vulnerability in YugaByte, Inc. Yugabyte DB on Windows, Linux, MacOS, iOS (DevopsBase.Java:execCommand, TableManager.Java:runCommand modules) allows API Manipulation, Privilege Abuse. This vulnerability is associated with program files backup.Py. This issue affects Yugabyte DB: Lesser then 2.2.0.0

CVSS3: 7.2
debian
почти 3 года назад

External Control of Critical State Data, Improper Control of Generatio ...

EPSS

Процентиль: 28%
0.001
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-642