Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qv32-5wm2-p32h

Опубликовано: 13 авг. 2024
Источник: github
Github: Прошло ревью
CVSS4: 9.3
CVSS3: 9.8

Описание

Command Injection in sequenceserver

Impact

Several HTTP endpoints did not properly sanitize user input and/or query parameters. This could be exploited to inject and run unwanted shell commands

Patches

Fixed in 3.1.2

Workarounds

No known workarounds

Пакеты

Наименование

sequenceserver

rubygems
Затронутые версииВерсия исправления

< 3.1.2

3.1.2

EPSS

Процентиль: 81%
0.01618
Низкий

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-77

Связанные уязвимости

CVSS3: 9.8
nvd
больше 1 года назад

SequenceServer lets you rapidly set up a BLAST+ server with an intuitive user interface for personal or group use. Several HTTP endpoints did not properly sanitize user input and/or query parameters. This could be exploited to inject and run unwanted shell commands. This vulnerability has been fixed in 3.1.2.

EPSS

Процентиль: 81%
0.01618
Низкий

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-77