Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cp28-pf73-xw7v

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Incomplete blacklist vulnerability in nrpc.c in Nagios Remote Plug-In Executor (NRPE) before 2.14 might allow remote attackers to execute arbitrary shell commands via "$()" shell metacharacters, which are processed by bash.

Incomplete blacklist vulnerability in nrpc.c in Nagios Remote Plug-In Executor (NRPE) before 2.14 might allow remote attackers to execute arbitrary shell commands via "$()" shell metacharacters, which are processed by bash.

EPSS

Процентиль: 99%
0.65724
Средний

Дефекты

CWE-20

Связанные уязвимости

ubuntu
около 13 лет назад

Incomplete blacklist vulnerability in nrpc.c in Nagios Remote Plug-In Executor (NRPE) before 2.14 might allow remote attackers to execute arbitrary shell commands via "$()" shell metacharacters, which are processed by bash.

redhat
больше 13 лет назад

Incomplete blacklist vulnerability in nrpc.c in Nagios Remote Plug-In Executor (NRPE) before 2.14 might allow remote attackers to execute arbitrary shell commands via "$()" shell metacharacters, which are processed by bash.

nvd
около 13 лет назад

Incomplete blacklist vulnerability in nrpc.c in Nagios Remote Plug-In Executor (NRPE) before 2.14 might allow remote attackers to execute arbitrary shell commands via "$()" shell metacharacters, which are processed by bash.

debian
около 13 лет назад

Incomplete blacklist vulnerability in nrpc.c in Nagios Remote Plug-In ...

EPSS

Процентиль: 99%
0.65724
Средний

Дефекты

CWE-20