Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-734q-6f9p-wxpv

Опубликовано: 16 дек. 2021
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

In StackStorm versions prior to 3.6.0, the jinja interpreter was not run in sandbox mode and thus allows execution of unsafe system commands. Jinja does not enable sandboxed mode by default due to backwards compatibility. Stackstorm now sets sandboxed mode for jinja by default.

In StackStorm versions prior to 3.6.0, the jinja interpreter was not run in sandbox mode and thus allows execution of unsafe system commands. Jinja does not enable sandboxed mode by default due to backwards compatibility. Stackstorm now sets sandboxed mode for jinja by default.

EPSS

Процентиль: 85%
0.02639
Низкий

8.8 High

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 8.8
nvd
около 4 лет назад

In StackStorm versions prior to 3.6.0, the jinja interpreter was not run in sandbox mode and thus allows execution of unsafe system commands. Jinja does not enable sandboxed mode by default due to backwards compatibility. Stackstorm now sets sandboxed mode for jinja by default.

EPSS

Процентиль: 85%
0.02639
Низкий

8.8 High

CVSS3

Дефекты

CWE-94