Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-23422

Опубликовано: 16 авг. 2021
Источник: nvd
CVSS3: 7.8
CVSS2: 6.8
EPSS Низкий

Описание

This affects the package bikeshed before 3.0.0. This can occur when an untrusted source file containing Inline Tag Command metadata is processed. When an arbitrary OS command is executed, the command output would be included in the HTML output.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:bikeshed_project:bikeshed:*:*:*:*:*:*:*:*
Версия до 3.0.0 (исключая)

EPSS

Процентиль: 42%
0.00203
Низкий

7.8 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-78

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 4 лет назад

This affects the package bikeshed before 3.0.0. This can occur when an untrusted source file containing Inline Tag Command metadata is processed. When an arbitrary OS command is executed, the command output would be included in the HTML output.

CVSS3: 7.8
github
больше 4 лет назад

OS Command Injection in bikeshed

EPSS

Процентиль: 42%
0.00203
Низкий

7.8 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-78