Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-44794

Опубликовано: 07 нояб. 2022
Источник: nvd
CVSS3: 8.8
EPSS Низкий

Описание

An issue was discovered in Object First Ootbi BETA build 1.0.7.712. Management protocol has a flow which allows a remote attacker to execute arbitrary Bash code with root privileges. The command that sets the hostname doesn't validate input parameters. As a result, arbitrary data goes directly to the Bash interpreter. An attacker would need credentials to exploit this vulnerability. This is fixed in Object First Ootbi BETA build 1.0.13.1611.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:objectfirst:ootbi:*:*:*:*:*:*:*:*
Версия до 1.0.13.1611 (исключая)

EPSS

Процентиль: 72%
0.00729
Низкий

8.8 High

CVSS3

Дефекты

NVD-CWE-noinfo
CWE-94

Связанные уязвимости

CVSS3: 8.8
github
больше 3 лет назад

An issue was discovered in Object First 1.0.7.712. Management protocol has a flow which allows a remote attacker to execute arbitrary Bash code with root privileges. The command that sets the hostname doesn't validate input parameters. As a result, arbitrary data goes directly to the Bash interpreter. An attacker would need credentials to exploit this vulnerability. This is fixed in 1.0.13.1611.

EPSS

Процентиль: 72%
0.00729
Низкий

8.8 High

CVSS3

Дефекты

NVD-CWE-noinfo
CWE-94