Описание
acme.sh before 3.0.6 runs arbitrary commands from a remote server via eval, as exploited in the wild in June 2023.
Ссылки
- Mailing ListThird Party Advisory
- Issue TrackingThird Party Advisory
- Release Notes
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Mailing ListThird Party Advisory
- Issue TrackingThird Party Advisory
- Release Notes
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 3.0.6 (исключая)
cpe:2.3:a:acme.sh_project:acme.sh:*:*:*:*:*:*:*:*
EPSS
Процентиль: 49%
0.00262
Низкий
9.8 Critical
CVSS3
Дефекты
NVD-CWE-noinfo
CWE-94
Связанные уязвимости
CVSS3: 9.8
debian
больше 2 лет назад
acme.sh before 3.0.6 runs arbitrary commands from a remote server via ...
CVSS3: 9.8
github
больше 2 лет назад
acme.sh before 3.0.6 runs arbitrary commands from a remote server via eval, as exploited in the wild in June 2023.
CVSS3: 8.1
fstec
больше 2 лет назад
Уязвимость функции Eval клиента протокола ACME Acme.sh, позволяющая нарушителю выполнить произвольный код
EPSS
Процентиль: 49%
0.00262
Низкий
9.8 Critical
CVSS3
Дефекты
NVD-CWE-noinfo
CWE-94