Описание
BES before 3.5.0 in OPeNDAP 4 (Hydrax) before 1.2.1 does not properly handle compressed files, which allows remote attackers to upload arbitrary files or execute arbitrary commands via a crafted compressed file.
Ссылки
- PatchUS Government Resource
- Patch
- Patch
- PatchUS Government Resource
- Patch
- Patch
Уязвимые конфигурации
Конфигурация 1Версия до 3.4.2 (включая)
Одно из
cpe:2.3:a:opendap:bes:*:*:*:*:*:*:*:*
cpe:2.3:a:opendap:hyrax:1.2:*:*:*:*:*:*:*
EPSS
Процентиль: 74%
0.00803
Низкий
7.5 High
CVSS2
Дефекты
NVD-CWE-Other
Связанные уязвимости
github
почти 4 года назад
BES before 3.5.0 in OPeNDAP 4 (Hydrax) before 1.2.1 does not properly handle compressed files, which allows remote attackers to upload arbitrary files or execute arbitrary commands via a crafted compressed file.
EPSS
Процентиль: 74%
0.00803
Низкий
7.5 High
CVSS2
Дефекты
NVD-CWE-Other