Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mqcp-p2hv-vw6x

Опубликовано: 20 июл. 2025
Источник: github
Github: Прошло ревью
CVSS3: 7.8

Описание

Withdrawn Advisory: Thor can construct an unsafe shell command from library input.

Withdrawn Advisory

This advisory has been withdrawn because the method described can only be used with arguments that are controlled by Thor, and an external attacker cannot access the functionality described in the body of the CVE. This link is maintained to preserve external references.

Original Description

Thor before 1.4.0 can construct an unsafe shell command from library input.

Пакеты

Наименование

thor

rubygems
Затронутые версииВерсия исправления

< 1.4.0

1.4.0

EPSS

Процентиль: 5%
0.00024
Низкий

7.8 High

CVSS3

Дефекты

CWE-78

Связанные уязвимости

CVSS3: 2.8
ubuntu
около 1 месяца назад

Thor before 1.4.0 can construct an unsafe shell command from library input. NOTE: this is disputed by the Supplier because "the method that was fixed can only be used with arguments that are controlled by Thor, and there is no way an attacker can take control of those arguments."

CVSS3: 2.8
redhat
около 1 месяца назад

Thor before 1.4.0 can construct an unsafe shell command from library input. NOTE: this is disputed by the Supplier because "the method that was fixed can only be used with arguments that are controlled by Thor, and there is no way an attacker can take control of those arguments."

CVSS3: 2.8
nvd
около 1 месяца назад

Thor before 1.4.0 can construct an unsafe shell command from library input. NOTE: this is disputed by the Supplier because "the method that was fixed can only be used with arguments that are controlled by Thor, and there is no way an attacker can take control of those arguments."

CVSS3: 2.8
debian
около 1 месяца назад

Thor before 1.4.0 can construct an unsafe shell command from library i ...

EPSS

Процентиль: 5%
0.00024
Низкий

7.8 High

CVSS3

Дефекты

CWE-78