Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-21235

Опубликовано: 01 апр. 2023
Источник: redhat
CVSS3: 9.8
EPSS Низкий

Описание

The package github.com/masterminds/vcs before 1.13.3 are vulnerable to Command Injection via argument injection. When hg is executed, argument strings are passed to hg in a way that additional flags can be set. The additional flags can be used to perform a command injection.

A flaw was found in the VCS package, caused by improper validation of user-supplied input. By using a specially-crafted argument, a remote attacker could execute arbitrary commands on the system.

Отчет

In Red Hat OpenStack, the 'github.com/Masterminds/vcs' is a transitive dependency and is not used by operators directly which reduces the chances for successful exploitation. Hence, the impact for OpenStack is reduced to moderate.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Developer Tools and ServiceshelmNot affected
OpenShift Serverlessopenshift-serverless-1/ingress-rhel8-operatorAffected
OpenShift Serverlessopenshift-serverless-1/knative-rhel8-operatorAffected
OpenShift Serverlessopenshift-serverless-1/serverless-rhel8-operatorAffected
Red Hat 3scale API Management Platform 2github-Masterminds-vcsNot affected
Red Hat Advanced Cluster Management for Kubernetes 2acm-multicluster-globalhub-agent-containerNot affected
Red Hat Advanced Cluster Management for Kubernetes 2acm-multicluster-globalhub-manager-containerNot affected
Red Hat Advanced Cluster Management for Kubernetes 2acm-multicluster-globalhub-operator-bundle-containerNot affected
Red Hat Advanced Cluster Management for Kubernetes 2acm-multicluster-globalhub-operator-containerNot affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/acm-cluster-proxy-rhel8Not affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-88
https://bugzilla.redhat.com/show_bug.cgi?id=2215317github.com/Masterminds/vcs: Command Injection via argument injection

EPSS

Процентиль: 61%
0.00412
Низкий

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 8.1
nvd
почти 4 года назад

The package github.com/masterminds/vcs before 1.13.3 are vulnerable to Command Injection via argument injection. When hg is executed, argument strings are passed to hg in a way that additional flags can be set. The additional flags can be used to perform a command injection.

msrc
5 месяцев назад

Command Injection

CVSS3: 9.8
github
почти 4 года назад

Command Injection Vulnerability with Mercurial in VCS

EPSS

Процентиль: 61%
0.00412
Низкий

9.8 Critical

CVSS3