Описание
The package com.google.cloud.tools:jib-core before 0.22.0 are vulnerable to Remote Code Execution (RCE) via the isDockerInstalled function, due to attempting to execute input.
Ссылки
- PatchThird Party Advisory
- PatchThird Party Advisory
- Third Party Advisory
- PatchThird Party Advisory
- PatchThird Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 0.22.0 (исключая)
cpe:2.3:a:jib_project:jib:*:*:*:*:*:*:*:*
EPSS
Процентиль: 88%
0.03874
Низкий
5.6 Medium
CVSS3
9.8 Critical
CVSS3
Дефекты
NVD-CWE-noinfo
Связанные уязвимости
CVSS3: 9.8
redhat
больше 3 лет назад
The package com.google.cloud.tools:jib-core before 0.22.0 are vulnerable to Remote Code Execution (RCE) via the isDockerInstalled function, due to attempting to execute input.
CVSS3: 9.8
github
больше 3 лет назад
com.google.cloud.tools:jib-core vulnerable to Remote Code Execution (RCE)
EPSS
Процентиль: 88%
0.03874
Низкий
5.6 Medium
CVSS3
9.8 Critical
CVSS3
Дефекты
NVD-CWE-noinfo