Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w8cj-mvf9-mpc9

Опубликовано: 06 мая 2021
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

OS Command injection in Bolt

Bolt before 3.7.2 does not restrict filter options in a Request in the Twig context, and is therefore inconsistent with the "How to Harden Your PHP for Better Security" guidance.

Пакеты

Наименование

bolt/bolt

composer
Затронутые версииВерсия исправления

< 3.7.2

3.7.2

EPSS

Процентиль: 57%
0.00344
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-78

Связанные уязвимости

CVSS3: 5.3
nvd
около 5 лет назад

Bolt before 3.7.2 does not restrict filter options in a Request in the Twig context, and is therefore inconsistent with the "How to Harden Your PHP for Better Security" guidance.

CVSS3: 5.3
msrc
4 месяца назад

Bolt before 3.7.2 does not restrict filter options in a Request in the Twig context, and is therefore inconsistent with the "How to Harden Your PHP for Better Security" guidance.

EPSS

Процентиль: 57%
0.00344
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-78