Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-7032

Опубликовано: 14 фев. 2018
Источник: nvd
CVSS3: 7.5
CVSS2: 5.1
EPSS Низкий

Описание

webcheckout in myrepos through 1.20171231 does not sanitize URLs that are passed to git clone, allowing a malicious website operator or a MitM attacker to take advantage of it for arbitrary code execution, as demonstrated by an "ext::sh -c" attack or an option injection attack.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:myrepos_project:myrepos:*:*:*:*:*:*:*:*
Версия до 1.20171231 (включая)

EPSS

Процентиль: 59%
0.00385
Низкий

7.5 High

CVSS3

5.1 Medium

CVSS2

Дефекты

CWE-74

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 8 лет назад

webcheckout in myrepos through 1.20171231 does not sanitize URLs that are passed to git clone, allowing a malicious website operator or a MitM attacker to take advantage of it for arbitrary code execution, as demonstrated by an "ext::sh -c" attack or an option injection attack.

CVSS3: 7.5
debian
почти 8 лет назад

webcheckout in myrepos through 1.20171231 does not sanitize URLs that ...

CVSS3: 7.5
github
больше 3 лет назад

webcheckout in myrepos through 1.20171231 does not sanitize URLs that are passed to git clone, allowing a malicious website operator or a MitM attacker to take advantage of it for arbitrary code execution, as demonstrated by an "ext::sh -c" attack or an option injection attack.

EPSS

Процентиль: 59%
0.00385
Низкий

7.5 High

CVSS3

5.1 Medium

CVSS2

Дефекты

CWE-74