Описание
A flaw has been found in wong2 mcp-cli 1.13.0. Affected is the function redirectToAuthorization of the file /src/oauth/provider.js of the component oAuth Handler. This manipulation causes os command injection. The attack may be initiated remotely. The attack is considered to have high complexity. The exploitability is told to be difficult. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
- Permissions RequiredVDB Entry
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:wong2:mcp-cli:1.13.0:*:*:*:*:*:*:*
EPSS
Процентиль: 37%
0.00156
Низкий
5.6 Medium
CVSS3
8.1 High
CVSS3
5.1 Medium
CVSS2
Дефекты
CWE-77
CWE-78
Связанные уязвимости
EPSS
Процентиль: 37%
0.00156
Низкий
5.6 Medium
CVSS3
8.1 High
CVSS3
5.1 Medium
CVSS2
Дефекты
CWE-77
CWE-78