Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-25626

Опубликовано: 19 фев. 2024
Источник: nvd
CVSS3: 8.8
CVSS3: 9.8
EPSS Низкий

Описание

Yocto Project is an open source collaboration project that helps developers create custom Linux-based systems regardless of the hardware architecture. In Yocto Projects Bitbake before 2.6.2 (before and included Yocto Project 4.3.1), with the Toaster server (included in bitbake) running, missing input validation allows an attacker to perform a remote code execution in the server's shell via a crafted HTTP request. Authentication is not necessary. Toaster server execution has to be specifically run and is not the default for Bitbake command line builds, it is only used for the Toaster web based user interface to Bitbake. The fix has been backported to the bitbake included with Yocto Project 5.0, 3.1.31, 4.0.16, and 4.3.2.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:linuxfoundation:yocto:*:*:*:*:*:*:*:*
Версия до 3.1.31 (исключая)
cpe:2.3:a:linuxfoundation:yocto:*:*:*:*:*:*:*:*
Версия от 3.2 (включая) до 4.0.16 (исключая)
cpe:2.3:a:linuxfoundation:yocto:*:*:*:*:*:*:*:*
Версия от 4.1 (включая) до 4.3.2 (исключая)

EPSS

Процентиль: 80%
0.01379
Низкий

8.8 High

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-78
CWE-78

EPSS

Процентиль: 80%
0.01379
Низкий

8.8 High

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-78
CWE-78