Описание
Starship is a cross-shell prompt. Starting in version 1.0.0 and prior to version 1.20.0, undocumented and unpredictable shell expansion and/or quoting rules make it easily to accidentally cause shell injection when using custom commands with starship in bash. This issue only affects users with custom commands, so the scope is limited, and without knowledge of others' commands, it could be hard to successfully target someone. Version 1.20.0 fixes the vulnerability.
Ссылки
- Patch
- Release Notes
- ExploitVendor Advisory
- Patch
- Release Notes
- ExploitVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 1.0.0 (включая) до 1.20.0 (исключая)
cpe:2.3:a:starship:starship:*:*:*:*:*:*:*:*
EPSS
Процентиль: 53%
0.00301
Низкий
7.4 High
CVSS3
7 High
CVSS3
Дефекты
CWE-77
CWE-78
Связанные уязвимости
CVSS3: 7.4
debian
больше 1 года назад
Starship is a cross-shell prompt. Starting in version 1.0.0 and prior ...
CVSS3: 7.4
github
больше 1 года назад
Starship vulnerable to shell injection via undocumented, unpredictable shell expansion in custom commands
EPSS
Процентиль: 53%
0.00301
Низкий
7.4 High
CVSS3
7 High
CVSS3
Дефекты
CWE-77
CWE-78