Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-26301

Опубликовано: 20 сент. 2021
Источник: redhat
CVSS3: 5.4
EPSS Низкий

Описание

ssh2 is client and server modules written in pure JavaScript for node.js. In ssh2 before version 1.4.0 there is a command injection vulnerability. The issue only exists on Windows. This issue may lead to remote code execution if a client of the library calls the vulnerable method with untrusted input. This is fixed in version 1.4.0.

A flaw was found in nodejs-ssh2. An OS command injection attack on Windows allows an attacker to perform remote code execution and potentially execute arbitrary code. The highest threat from this vulnerability is to confidentiality and integrity.

Отчет

This issue affects ssh2 as shipped with all versions of Red Hat Openshift Container Storage and Red Hat Openshift Data Foundations. However, this flaw requires a Windows based attack, and therefore, the impact is adjusted accordingly to a moderate risk.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Openshift Data Foundation 4noobaa-core-containerAffected
Red Hat OpenShift Container Storage 4.8.0 on RHEL-8ocs4/cephcsi-rhel8FixedRHSA-2021:484529.11.2021
Red Hat OpenShift Container Storage 4.8.0 on RHEL-8ocs4/mcg-core-rhel8FixedRHSA-2021:484529.11.2021
Red Hat OpenShift Container Storage 4.8.0 on RHEL-8ocs4/mcg-rhel8-operatorFixedRHSA-2021:484529.11.2021
Red Hat OpenShift Container Storage 4.8.0 on RHEL-8ocs4/ocs-must-gather-rhel8FixedRHSA-2021:484529.11.2021
Red Hat OpenShift Container Storage 4.8.0 on RHEL-8ocs4/ocs-operator-bundleFixedRHSA-2021:484529.11.2021
Red Hat OpenShift Container Storage 4.8.0 on RHEL-8ocs4/ocs-rhel8-operatorFixedRHSA-2021:484529.11.2021
Red Hat OpenShift Container Storage 4.8.0 on RHEL-8ocs4/rook-ceph-rhel8-operatorFixedRHSA-2021:484529.11.2021
Red Hat OpenShift Container Storage 4.8.0 on RHEL-8ocs4/volume-replication-rhel8-operatorFixedRHSA-2021:484529.11.2021

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-78
https://bugzilla.redhat.com/show_bug.cgi?id=2006958nodejs-ssh2: Command injection by calling vulnerable method with untrusted input

EPSS

Процентиль: 90%
0.05066
Низкий

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
больше 4 лет назад

ssh2 is client and server modules written in pure JavaScript for node.js. In ssh2 before version 1.4.0 there is a command injection vulnerability. The issue only exists on Windows. This issue may lead to remote code execution if a client of the library calls the vulnerable method with untrusted input. This is fixed in version 1.4.0.

CVSS3: 7.5
github
больше 4 лет назад

OS Command Injection in ssh2

EPSS

Процентиль: 90%
0.05066
Низкий

5.4 Medium

CVSS3