Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wp4w-52jh-8g3x

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

Insufficient sanitization of environment variables passed to rsync can bypass the restrictions imposed by rssh, a restricted shell that should restrict users to perform only rsync operations, resulting in the execution of arbitrary shell commands.

Insufficient sanitization of environment variables passed to rsync can bypass the restrictions imposed by rssh, a restricted shell that should restrict users to perform only rsync operations, resulting in the execution of arbitrary shell commands.

EPSS

Процентиль: 93%
0.1026
Средний

9.8 Critical

CVSS3

Дефекты

CWE-665

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 7 лет назад

Insufficient sanitization of environment variables passed to rsync can bypass the restrictions imposed by rssh, a restricted shell that should restrict users to perform only rsync operations, resulting in the execution of arbitrary shell commands.

CVSS3: 9.8
nvd
около 7 лет назад

Insufficient sanitization of environment variables passed to rsync can bypass the restrictions imposed by rssh, a restricted shell that should restrict users to perform only rsync operations, resulting in the execution of arbitrary shell commands.

CVSS3: 9.8
debian
около 7 лет назад

Insufficient sanitization of environment variables passed to rsync can ...

CVSS3: 9.8
fstec
около 7 лет назад

Уязвимость обработчика команды rsync командной оболочки rssh, связанная с недостаточной проверкой вводимых данных, позволяющая нарушителю выполнить произвольную команду

EPSS

Процентиль: 93%
0.1026
Средний

9.8 Critical

CVSS3

Дефекты

CWE-665