Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vx65-qfv7-jcf4

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

Insufficient sanitization of arguments passed to rsync can bypass the restrictions imposed by rssh, a restricted shell that should restrict users to perform only rsync operations, resulting in the execution of arbitrary shell commands.

Insufficient sanitization of arguments passed to rsync can bypass the restrictions imposed by rssh, a restricted shell that should restrict users to perform only rsync operations, resulting in the execution of arbitrary shell commands.

EPSS

Процентиль: 94%
0.12799
Средний

9.8 Critical

CVSS3

Дефекты

CWE-88

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 7 лет назад

Insufficient sanitization of arguments passed to rsync can bypass the restrictions imposed by rssh, a restricted shell that should restrict users to perform only rsync operations, resulting in the execution of arbitrary shell commands.

CVSS3: 9.8
nvd
около 7 лет назад

Insufficient sanitization of arguments passed to rsync can bypass the restrictions imposed by rssh, a restricted shell that should restrict users to perform only rsync operations, resulting in the execution of arbitrary shell commands.

CVSS3: 9.8
debian
около 7 лет назад

Insufficient sanitization of arguments passed to rsync can bypass the ...

CVSS3: 9.8
fstec
около 7 лет назад

Уязвимость реализации команды «rsync» командной оболочки rssh, позволяющая нарушителю выполнять произвольные команды оболочки rssh

EPSS

Процентиль: 94%
0.12799
Средний

9.8 Critical

CVSS3

Дефекты

CWE-88