Описание
Uncontrolled Search Path Element in sharkdp/bat
bat on windows before 0.18.2 executes programs named less.exe from the current working directory. This can lead to unintended code execution.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2021-36753
- https://github.com/sharkdp/bat/pull/1724
- https://github.com/sharkdp/bat/commit/bf2b2df9c9e218e35e5a38ce3d03cffb7c363956
- https://github.com/sharkdp/bat/releases/tag/v0.18.2
- https://rustsec.org/advisories/RUSTSEC-2021-0106.html
- https://vuln.ryotak.me/advisories/53
Пакеты
Наименование
bat
rust
Затронутые версииВерсия исправления
< 0.18.2
0.18.2
Связанные уязвимости
CVSS3: 7.8
nvd
больше 4 лет назад
sharkdp BAT before 0.18.2 executes less.exe from the current working directory.