Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-66m2-493m-crh2

Опубликовано: 25 сент. 2023
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

Searchor CLI's Search vulnerable to Arbitrary Code using Eval

An issue in Arjun Sharda's Searchor before version v.2.4.2 allows an attacker to execute arbitrary code via a crafted script to the eval() function in Searchor's src/searchor/main.py file, affecting the search feature in Searchor's CLI (Command Line Interface).

Impact

Versions equal to, or below 2.4.1 are affected.

Patches

Versions above, or equal to 2.4.2 have patched the vulnerability.

References

https://github.com/nikn0laty/Exploit-for-Searchor-2.4.0-Arbitrary-CMD-Injection https://github.com/nexis-nexis/Searchor-2.4.0-POC-Exploit- https://github.com/jonnyzar/POC-Searchor-2.4.2 https://github.com/ArjunSharda/Searchor/pull/130

Пакеты

Наименование

searchor

pip
Затронутые версииВерсия исправления

<= 2.4.1

2.4.2

EPSS

Процентиль: 96%
0.29638
Средний

9.8 Critical

CVSS3

Дефекты

CWE-74
CWE-94

Связанные уязвимости

CVSS3: 9.8
nvd
около 2 лет назад

main.py in Searchor before 2.4.2 uses eval on CLI input, which may cause unexpected code execution.

EPSS

Процентиль: 96%
0.29638
Средний

9.8 Critical

CVSS3

Дефекты

CWE-74
CWE-94