Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-23556

Опубликовано: 17 мар. 2022
Источник: nvd
CVSS3: 6.4
CVSS3: 8
CVSS2: 6
EPSS Низкий

Описание

The package guake before 3.8.5 are vulnerable to Exposed Dangerous Method or Function due to the exposure of execute_command and execute_command_by_uuid methods via the d-bus interface, which makes it possible for a malicious user to run an arbitrary command via the d-bus method. Note: Exploitation requires the user to have installed another malicious program that will be able to send dbus signals or run terminal commands.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:guake-project:guake:*:*:*:*:*:*:*:*
Версия до 3.8.5 (исключая)

EPSS

Процентиль: 74%
0.00823
Низкий

6.4 Medium

CVSS3

8 High

CVSS3

6 Medium

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

CVSS3: 6.4
ubuntu
почти 4 года назад

The package guake before 3.8.5 are vulnerable to Exposed Dangerous Method or Function due to the exposure of execute_command and execute_command_by_uuid methods via the d-bus interface, which makes it possible for a malicious user to run an arbitrary command via the d-bus method. **Note:** Exploitation requires the user to have installed another malicious program that will be able to send dbus signals or run terminal commands.

CVSS3: 6.4
debian
почти 4 года назад

The package guake before 3.8.5 are vulnerable to Exposed Dangerous Met ...

CVSS3: 6.4
github
почти 4 года назад

Command injection in guake

EPSS

Процентиль: 74%
0.00823
Низкий

6.4 Medium

CVSS3

8 High

CVSS3

6 Medium

CVSS2

Дефекты

NVD-CWE-Other