Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9h25-7cgq-fhvv

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Ruckus through 1.5.1.0.21 is affected by remote command injection. An authenticated user can submit a query to the API (/service/v1/createUser endpoint), injecting arbitrary commands that will be executed as root user via web.py.

Ruckus through 1.5.1.0.21 is affected by remote command injection. An authenticated user can submit a query to the API (/service/v1/createUser endpoint), injecting arbitrary commands that will be executed as root user via web.py.

EPSS

Процентиль: 97%
0.41549
Средний

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 8.8
nvd
больше 5 лет назад

Ruckus through 1.5.1.0.21 is affected by remote command injection. An authenticated user can submit a query to the API (/service/v1/createUser endpoint), injecting arbitrary commands that will be executed as root user via web.py.

EPSS

Процентиль: 97%
0.41549
Средний

Дефекты

CWE-862