Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4hwf-q27j-2mmh

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.6

Описание

OnApp before 5.0.0-88, 5.5.0-93, and 6.0.0-196 allows an attacker to run arbitrary commands with root privileges on servers managed by OnApp for XEN/KVM hypervisors. To exploit the vulnerability an attacker has to have control of a single server on a given cloud (e.g. by renting one). From the source server, the attacker can craft any command and trigger the OnApp platform to execute that command with root privileges on a target server.

OnApp before 5.0.0-88, 5.5.0-93, and 6.0.0-196 allows an attacker to run arbitrary commands with root privileges on servers managed by OnApp for XEN/KVM hypervisors. To exploit the vulnerability an attacker has to have control of a single server on a given cloud (e.g. by renting one). From the source server, the attacker can craft any command and trigger the OnApp platform to execute that command with root privileges on a target server.

EPSS

Процентиль: 52%
0.00295
Низкий

6.6 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.6
nvd
больше 6 лет назад

OnApp before 5.0.0-88, 5.5.0-93, and 6.0.0-196 allows an attacker to run arbitrary commands with root privileges on servers managed by OnApp for XEN/KVM hypervisors. To exploit the vulnerability an attacker has to have control of a single server on a given cloud (e.g. by renting one). From the source server, the attacker can craft any command and trigger the OnApp platform to execute that command with root privileges on a target server.

EPSS

Процентиль: 52%
0.00295
Низкий

6.6 Medium

CVSS3