Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-87cj-px37-rc3x

Опубликовано: 30 авг. 2021
Источник: github
Github: Прошло ревью
CVSS3: 7.8

Описание

OS Command Injection in bikeshed

This affects the package bikeshed before 3.0.0. This can occur when an untrusted source file containing Inline Tag Command metadata is processed. When an arbitrary OS command is executed, the command output would be included in the HTML output.

Пакеты

Наименование

bikeshed

pip
Затронутые версииВерсия исправления

< 3.0.0

3.0.0

EPSS

Процентиль: 42%
0.00203
Низкий

7.8 High

CVSS3

Дефекты

CWE-78

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 4 лет назад

This affects the package bikeshed before 3.0.0. This can occur when an untrusted source file containing Inline Tag Command metadata is processed. When an arbitrary OS command is executed, the command output would be included in the HTML output.

CVSS3: 7.8
nvd
больше 4 лет назад

This affects the package bikeshed before 3.0.0. This can occur when an untrusted source file containing Inline Tag Command metadata is processed. When an arbitrary OS command is executed, the command output would be included in the HTML output.

EPSS

Процентиль: 42%
0.00203
Низкий

7.8 High

CVSS3

Дефекты

CWE-78