Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p9qj-4rjp-j3w9

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.8

Описание

Apache Directory Studio Command Injection

The CSV export in Apache LDAP Studio and Apache Directory Studio before 2.0.0-M10 does not properly escape field values, which might allow attackers to execute arbitrary commands by leveraging a crafted LDAP entry that is interpreted as a formula when imported into a spreadsheet.

Пакеты

Наименование

org.apache.directory.studio:org.apache.directory.studio.ldapbrowser.core

maven
Затронутые версииВерсия исправления

< 2.0.0.v20151221-M10

2.0.0.v20151221-M10

EPSS

Процентиль: 80%
0.01431
Низкий

7.8 High

CVSS3

Дефекты

CWE-77

Связанные уязвимости

CVSS3: 7.8
redhat
почти 10 лет назад

The CSV export in Apache LDAP Studio and Apache Directory Studio before 2.0.0-M10 does not properly escape field values, which might allow attackers to execute arbitrary commands by leveraging a crafted LDAP entry that is interpreted as a formula when imported into a spreadsheet.

CVSS3: 7.8
nvd
почти 10 лет назад

The CSV export in Apache LDAP Studio and Apache Directory Studio before 2.0.0-M10 does not properly escape field values, which might allow attackers to execute arbitrary commands by leveraging a crafted LDAP entry that is interpreted as a formula when imported into a spreadsheet.

CVSS3: 7.8
debian
почти 10 лет назад

The CSV export in Apache LDAP Studio and Apache Directory Studio befor ...

EPSS

Процентиль: 80%
0.01431
Низкий

7.8 High

CVSS3

Дефекты

CWE-77