Описание
A vulnerability was detected in PicoClaw up to 0.2.4. Impacted is an unknown function of the file /api/gateway/restart of the component Web Launcher Management Plane. Performing a manipulation results in command injection. It is possible to initiate the attack remotely. The project was informed of the problem early through an issue report but has not responded yet.
Ссылки
- ExploitIssue TrackingMitigationVendor Advisory
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
- Permissions RequiredVDB Entry
Уязвимые конфигурации
Конфигурация 1Версия до 0.2.4 (включая)
cpe:2.3:a:sipeed:picoclaw:*:*:*:*:*:go:*:*
EPSS
Процентиль: 86%
0.03132
Низкий
7.3 High
CVSS3
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-74
Связанные уязвимости
CVSS3: 7.3
github
3 месяца назад
PicoClaw has an Injection issue in its Web Launcher Management Plane component
EPSS
Процентиль: 86%
0.03132
Низкий
7.3 High
CVSS3
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-74