Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vmx9-qv3g-pj44

Опубликовано: 13 янв. 2022
Источник: github
Github: Не прошло ревью

Описание

An issue was discovered in CALDERA 2.8.1. It contains multiple startup "requirements" that execute commands when starting the server. Because these commands can be changed via the REST API, an authenticated user can insert arbitrary commands that will execute when the server is restarted.

An issue was discovered in CALDERA 2.8.1. It contains multiple startup "requirements" that execute commands when starting the server. Because these commands can be changed via the REST API, an authenticated user can insert arbitrary commands that will execute when the server is restarted.

EPSS

Процентиль: 88%
0.04005
Низкий

Дефекты

CWE-77

Связанные уязвимости

CVSS3: 8.8
nvd
около 4 лет назад

An issue was discovered in CALDERA 2.8.1. It contains multiple startup "requirements" that execute commands when starting the server. Because these commands can be changed via the REST API, an authenticated user can insert arbitrary commands that will execute when the server is restarted.

EPSS

Процентиль: 88%
0.04005
Низкий

Дефекты

CWE-77