Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5ww9-9qp2-x524

Опубликовано: 24 июн. 2022
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

Improper handling of double quotes in file name in Diffy in Windows environment

The function that calls the diff tool in versions of Diffy prior to 3.4.1 does not properly handle double quotes in a filename when run in a Windows environment. This allows attackers to execute arbitrary commands via a crafted string.

Пакеты

Наименование

diffy

rubygems
Затронутые версииВерсия исправления

< 3.4.1

3.4.1

EPSS

Процентиль: 67%
0.0054
Низкий

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 3 лет назад

The function that calls the diff tool in Diffy 3.4.1 does not properly handle double quotes in a filename when run in a windows environment. This allows attackers to execute arbitrary commands via a crafted string.

CVSS3: 7.5
redhat
больше 3 лет назад

The function that calls the diff tool in Diffy 3.4.1 does not properly handle double quotes in a filename when run in a windows environment. This allows attackers to execute arbitrary commands via a crafted string.

CVSS3: 9.8
nvd
больше 3 лет назад

The function that calls the diff tool in Diffy 3.4.1 does not properly handle double quotes in a filename when run in a windows environment. This allows attackers to execute arbitrary commands via a crafted string.

CVSS3: 9.8
debian
больше 3 лет назад

The function that calls the diff tool in Diffy 3.4.1 does not properly ...

EPSS

Процентиль: 67%
0.0054
Низкий

9.8 Critical

CVSS3