Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cp28-pf73-xw7v

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Incomplete blacklist vulnerability in nrpc.c in Nagios Remote Plug-In Executor (NRPE) before 2.14 might allow remote attackers to execute arbitrary shell commands via "$()" shell metacharacters, which are processed by bash.

Incomplete blacklist vulnerability in nrpc.c in Nagios Remote Plug-In Executor (NRPE) before 2.14 might allow remote attackers to execute arbitrary shell commands via "$()" shell metacharacters, which are processed by bash.

EPSS

Процентиль: 99%
0.76437
Высокий

Дефекты

CWE-20

Связанные уязвимости

ubuntu
больше 12 лет назад

Incomplete blacklist vulnerability in nrpc.c in Nagios Remote Plug-In Executor (NRPE) before 2.14 might allow remote attackers to execute arbitrary shell commands via "$()" shell metacharacters, which are processed by bash.

redhat
почти 13 лет назад

Incomplete blacklist vulnerability in nrpc.c in Nagios Remote Plug-In Executor (NRPE) before 2.14 might allow remote attackers to execute arbitrary shell commands via "$()" shell metacharacters, which are processed by bash.

nvd
больше 12 лет назад

Incomplete blacklist vulnerability in nrpc.c in Nagios Remote Plug-In Executor (NRPE) before 2.14 might allow remote attackers to execute arbitrary shell commands via "$()" shell metacharacters, which are processed by bash.

debian
больше 12 лет назад

Incomplete blacklist vulnerability in nrpc.c in Nagios Remote Plug-In ...

EPSS

Процентиль: 99%
0.76437
Высокий

Дефекты

CWE-20