Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-1000487

Опубликовано: 09 окт. 2013
Источник: redhat
CVSS3: 7.8

Описание

Plexus-utils before 3.0.16 is vulnerable to command injection because it does not correctly process the contents of double quoted strings.

Отчет

This issue affects the versions of plexus-utils as shipped with Red Hat Enterprise Linux 7 as well as Red Hat Satellite 6.0 and 6.1. Red Hat Satellite 6.2 and later do not ship plexus-utils, as such they are not affected by this vulnerability. Red Hat Product Security has rated this issue as having Moderate security impact. A future update may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
JBoss Developer Studio 10plexus-utilsUnder investigation
JBoss Developer Studio 8plexus-utilsUnder investigation
Red Hat BPM Suite 6plexus-utilsNot affected
Red Hat Enterprise Linux 7plexus-utilsWill not fix
Red Hat Enterprise Linux 8plexus-utilsNot affected
Red Hat JBoss A-MQ 6plexus-utilsAffected
Red Hat JBoss BRMS 6plexus-utilsNot affected
Red Hat JBoss Data Virtualization 6plexus-utilsNot affected
Red Hat JBoss Fuse Service Works 6plexus-utilsWill not fix
Red Hat JBoss Portal 6plexus-utilsUnder investigation

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-78
https://bugzilla.redhat.com/show_bug.cgi?id=1532497plexus-utils: Mishandled strings in Commandline class allow for command injection

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 8 лет назад

Plexus-utils before 3.0.16 is vulnerable to command injection because it does not correctly process the contents of double quoted strings.

CVSS3: 9.8
nvd
около 8 лет назад

Plexus-utils before 3.0.16 is vulnerable to command injection because it does not correctly process the contents of double quoted strings.

CVSS3: 9.8
debian
около 8 лет назад

Plexus-utils before 3.0.16 is vulnerable to command injection because ...

CVSS3: 9.8
github
больше 3 лет назад

OS Command Injection in Plexus-utils

CVSS3: 9.8
fstec
около 8 лет назад

Уязвимость пакета Plexus-utils платформы расширенной аналитики IBM Netezza Analytics, позволяющая нарушителю выполнить произвольные команды

7.8 High

CVSS3