Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-49329

Опубликовано: 19 янв. 2024
Источник: nvd
CVSS3: 7.2
EPSS Низкий

Описание

Anomali Match before 4.6.2 allows OS Command Injection. An authenticated admin user can inject and execute operating system commands. This arises from improper handling of untrusted input, enabling an attacker to elevate privileges, execute system commands, and potentially compromise the underlying operating system. The fixed versions are 4.4.5, 4.5.4, and 4.6.2. The earliest affected version is 4.3.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:anomali:match:*:*:*:*:*:*:*:*
Версия от 4.3 (включая) до 4.4.5 (исключая)
cpe:2.3:a:anomali:match:*:*:*:*:*:*:*:*
Версия от 4.5.0 (включая) до 4.5.4 (исключая)
cpe:2.3:a:anomali:match:*:*:*:*:*:*:*:*
Версия от 4.6.0 (включая) до 4.6.2 (исключая)

EPSS

Процентиль: 50%
0.00266
Низкий

7.2 High

CVSS3

Дефекты

CWE-78
CWE-78

Связанные уязвимости

CVSS3: 7.2
github
около 2 лет назад

Anomali Match before 4.6.2 allows OS Command Injection. An authenticated admin user can inject and execute operating system commands. This arises from improper handling of untrusted input, enabling an attacker to elevate privileges, execute system commands, and potentially compromise the underlying operating system. The fixed versions are 4.4.5, 4.5.4, and 4.6.2. The earliest affected version is 4.3.

EPSS

Процентиль: 50%
0.00266
Низкий

7.2 High

CVSS3

Дефекты

CWE-78
CWE-78