Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-0542

Опубликовано: 09 янв. 2019
Источник: redhat
CVSS3: 7.5

Описание

A remote code execution vulnerability exists in Xterm.js when the component mishandles special characters, aka "Xterm Remote Code Execution Vulnerability." This affects xterm.js.

It was found that xterm.js does not sanitize terminal escape sequences in browser terminals allowing for execution of arbitrary commands. An attacker could exploit this by convincing a user with a xterm.js browser terminal to display an escape sequence by, for example, reading a from a log file containing attacker-controlled input.

Отчет

This issue affects both the atomic-openshift-web-console RPM and openshift3/ose-console container image shipped in OpenShift Container Platform. These components provide a web console for opening in-browser terminals in cluster pods. Successful exploitation of this issue would require an attacker to convince an authorized user to open an in-browser terminal on a target pod and execute a command that prints attacker-controlled input. Red Hat Product Security have rated this issue as having security impact of Moderate. A future update may address this issue.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Container Platform 4openshift4/ose-consoleNot affected
Red Hat OpenShift Container Platform 3.10atomic-openshift-web-consoleFixedRHSA-2019:255222.08.2019
Red Hat OpenShift Container Platform 3.11openshift3/apb-baseFixedRHBA-2019:095901.05.2019
Red Hat OpenShift Container Platform 3.11openshift3/apb-toolsFixedRHBA-2019:095901.05.2019
Red Hat OpenShift Container Platform 3.11openshift3/automation-broker-apbFixedRHBA-2019:095901.05.2019
Red Hat OpenShift Container Platform 3.11openshift3/csi-attacherFixedRHBA-2019:095901.05.2019
Red Hat OpenShift Container Platform 3.11openshift3/csi-driver-registrarFixedRHBA-2019:095901.05.2019
Red Hat OpenShift Container Platform 3.11openshift3/csi-livenessprobeFixedRHBA-2019:095901.05.2019
Red Hat OpenShift Container Platform 3.11openshift3/csi-provisionerFixedRHBA-2019:095901.05.2019
Red Hat OpenShift Container Platform 3.11openshift3/grafanaFixedRHBA-2019:095901.05.2019

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-77
https://bugzilla.redhat.com/show_bug.cgi?id=1668531xterm.js: Mishandling of special characters allows for remote code execution

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 7 лет назад

A remote code execution vulnerability exists in Xterm.js when the component mishandles special characters, aka "Xterm Remote Code Execution Vulnerability." This affects xterm.js.

CVSS3: 8.8
nvd
около 7 лет назад

A remote code execution vulnerability exists in Xterm.js when the component mishandles special characters, aka "Xterm Remote Code Execution Vulnerability." This affects xterm.js.

CVSS3: 8.8
debian
около 7 лет назад

A remote code execution vulnerability exists in Xterm.js when the comp ...

CVSS3: 8.8
github
около 7 лет назад

xterm vulnerable to remote code execution

CVSS3: 7.5
fstec
около 7 лет назад

Уязвимость библиотеки Xterm.js, связанная с отсутствием мер по очистке входных данных, позволяющая нарушителю выполнить произвольный код

7.5 High

CVSS3

Уязвимость CVE-2019-0542