Описание
Passbolt Api Remote code execution
Passbolt provides a way for system administrators to generate a PGP key for the server during installation. The wizard requests a username, an e-mail address and an optional comment. No escaping or verification is done by Passbolt, effectively allowing a user to inject bash code.
The impact is very high, but the probability is very low given that this vulnerability can only be exploited during Passbolt’s installation stage.
Пакеты
Наименование
passbolt/passbolt_api
composer
Затронутые версииВерсия исправления
< 2.7.0
2.7.0
8.1 High
CVSS3
Дефекты
CWE-78
8.1 High
CVSS3
Дефекты
CWE-78