Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3qcf-857g-5p4x

Опубликовано: 25 сент. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 8

Описание

IBM Aspera Console 3.4.0 through 3.4.4 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by a CSV injection vulnerability. By persuading a victim to open a specially crafted file, an attacker could exploit this vulnerability to execute arbitrary code on the system.

IBM Aspera Console 3.4.0 through 3.4.4 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by a CSV injection vulnerability. By persuading a victim to open a specially crafted file, an attacker could exploit this vulnerability to execute arbitrary code on the system.

EPSS

Процентиль: 52%
0.00288
Низкий

8 High

CVSS3

Дефекты

CWE-1236

Связанные уязвимости

CVSS3: 8
nvd
больше 1 года назад

IBM Aspera Console 3.4.0 through 3.4.4 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by a CSV injection vulnerability. By persuading a victim to open a specially crafted file, an attacker could exploit this vulnerability to execute arbitrary code on the system.

EPSS

Процентиль: 52%
0.00288
Низкий

8 High

CVSS3

Дефекты

CWE-1236