Описание
Net::Async::Statsd::Client versions through 0.005 for Perl allow metric injections.
The metric names are not checked for newlines, colons or pipes. Metrics generated from untrusted sources could inject additional statsd metrics.
Ссылки
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 0.005 (включая)
cpe:2.3:a:team:net\:\:async\:\:statsd\:\:client:*:*:*:*:*:perl:*:*
EPSS
Процентиль: 11%
0.00203
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-93
Связанные уязвимости
CVSS3: 6.5
github
около 2 месяцев назад
Net::Async::Statsd::Client versions through 0.005 for Perl allow metric injections. The metric names are not checked for newlines, colons or pipes. Metrics generated from untrusted sources could inject additional statsd metrics.
EPSS
Процентиль: 11%
0.00203
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-93