Описание
Sharetribe Go is a source available marketplace software. In affected versions operating system command injection is possible on installations of Sharetribe Go, that do not have a secret AWS Simple Notification Service (SNS) notification token configured via the sns_notification_token configuration parameter. This configuration parameter is unset by default. The vulnerability has been patched in version 10.2.1. Users who are unable to upgrade should set thesns_notification_token configuration parameter to a secret value.
Ссылки
- PatchThird Party Advisory
- Third Party Advisory
- Third Party Advisory
- PatchThird Party Advisory
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 10.2.1 (исключая)
cpe:2.3:a:sharetribe:sharetribe:*:*:*:*:*:*:*:*
EPSS
Процентиль: 92%
0.07631
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-78
CWE-78
EPSS
Процентиль: 92%
0.07631
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-78
CWE-78