Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wgmx-52ph-qqcw

Опубликовано: 10 окт. 2018
Источник: github
Github: Прошло ревью
CVSS3: 8.8

Описание

Qutebrowser CSRF Vulnerability

qutebrowser before version 1.4.1 is vulnerable to a cross-site request forgery flaw that allows websites to access qute://* URLs. A malicious website could exploit this to load a qute://settings/set URL, which then sets editor.command to a bash script, resulting in arbitrary code execution.

Пакеты

Наименование

qutebrowser

pip
Затронутые версииВерсия исправления

< 1.4.1

1.4.1

EPSS

Процентиль: 38%
0.00169
Низкий

8.8 High

CVSS3

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 9.3
ubuntu
больше 7 лет назад

qutebrowser before version 1.4.1 is vulnerable to a cross-site request forgery flaw that allows websites to access 'qute://*' URLs. A malicious website could exploit this to load a 'qute://settings/set' URL, which then sets 'editor.command' to a bash script, resulting in arbitrary code execution.

CVSS3: 9.3
nvd
больше 7 лет назад

qutebrowser before version 1.4.1 is vulnerable to a cross-site request forgery flaw that allows websites to access 'qute://*' URLs. A malicious website could exploit this to load a 'qute://settings/set' URL, which then sets 'editor.command' to a bash script, resulting in arbitrary code execution.

CVSS3: 9.3
debian
больше 7 лет назад

qutebrowser before version 1.4.1 is vulnerable to a cross-site request ...

suse-cvrf
больше 7 лет назад

Security update for qutebrowser

EPSS

Процентиль: 38%
0.00169
Низкий

8.8 High

CVSS3

Дефекты

CWE-352