Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3jcx-v57w-c6rq

Опубликовано: 01 дек. 2021
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

Vulnerability in dirhistory plugin Description: the widgets that go back and forward in the directory history, triggered by pressing Alt-Left and Alt-Right, use functions that unsafely execute eval on directory names. If you cd into a directory with a carefully-crafted name, then press Alt-Left, the system is subject to command injection. Impacted areas: - Functions pop_past and pop_future in dirhistory plugin.

Vulnerability in dirhistory plugin Description: the widgets that go back and forward in the directory history, triggered by pressing Alt-Left and Alt-Right, use functions that unsafely execute eval on directory names. If you cd into a directory with a carefully-crafted name, then press Alt-Left, the system is subject to command injection. Impacted areas: - Functions pop_past and pop_future in dirhistory plugin.

EPSS

Процентиль: 80%
0.0136
Низкий

8.8 High

CVSS3

Дефекты

CWE-78
CWE-94

Связанные уязвимости

CVSS3: 7.5
nvd
около 4 лет назад

Vulnerability in dirhistory plugin Description: the widgets that go back and forward in the directory history, triggered by pressing Alt-Left and Alt-Right, use functions that unsafely execute eval on directory names. If you cd into a directory with a carefully-crafted name, then press Alt-Left, the system is subject to command injection. Impacted areas: - Functions pop_past and pop_future in dirhistory plugin.

EPSS

Процентиль: 80%
0.0136
Низкий

8.8 High

CVSS3

Дефекты

CWE-78
CWE-94