Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-30205

Опубликовано: 25 мар. 2024
Источник: redhat
CVSS3: 7.8
EPSS Низкий

Описание

In Emacs before 29.3, Org mode considers contents of remote files to be trusted. This affects Org Mode before 9.6.23.

A flaw was found in Emacs. Org mode considers the content of remote files, such as files opened with TRAMP on remote systems, to be trusted, resulting in arbitrary code execution.

Отчет

To exploit this flaw, an attacker needs to trick a user into opening a crafted Org mode file from a remote system. For this reason, this flaw has been rated with a Moderate security impact. Within regulated environments, a combination of the following controls acts as a significant barrier to successfully exploiting a CWE-349: Acceptance of Extraneous Untrusted Data With Trusted Data vulnerability and therefore downgrades the severity of this particular CVE from Moderate to Low. Red Hat restricts access to all platform information by default, granting access only after successful hard token-based multi-factor authentication (MFA) and following least privilege principles to ensure that only authorized users and roles can execute or modify code. Event logs are collected and processed for centralization, correlation, analysis, monitoring, alerting, and retention, ensuring that audit records are generated for security-relevant events involving sensitive data and that mechanisms such as digital signatures and certificates verify the authenticity and origin of logged information. Certificates for both external infrastructure and internal cluster components are established and maintained within a secure environment, using cryptographic authentication to prevent the acceptance of untrusted data. The platform also enforces FIPS-validated cryptographic modules across all compute resources, helping ensure that intercepted data cannot be accessed or interpreted by unauthorized actors.

Меры по смягчению последствий

Do not open untrusted Org mode files from a remote system.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6emacsOut of support scope
Red Hat Enterprise Linux 7emacsOut of support scope
Red Hat Enterprise Linux 8emacsFixedRHSA-2024:698724.09.2024
Red Hat Enterprise Linux 8emacsFixedRHSA-2024:698724.09.2024
Red Hat Enterprise Linux 9emacsFixedRHSA-2024:930212.11.2024

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-349
https://bugzilla.redhat.com/show_bug.cgi?id=2280298emacs: Org mode considers contents of remote files to be trusted

EPSS

Процентиль: 7%
0.0003
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.1
ubuntu
около 1 года назад

In Emacs before 29.3, Org mode considers contents of remote files to be trusted. This affects Org Mode before 9.6.23.

CVSS3: 7.1
nvd
около 1 года назад

In Emacs before 29.3, Org mode considers contents of remote files to be trusted. This affects Org Mode before 9.6.23.

CVSS3: 7.1
msrc
12 месяцев назад

Описание отсутствует

CVSS3: 7.1
debian
около 1 года назад

In Emacs before 29.3, Org mode considers contents of remote files to b ...

CVSS3: 7.1
github
около 1 года назад

In Emacs before 29.3, Org mode considers contents of remote files to be trusted. This affects Org Mode before 9.6.23.

EPSS

Процентиль: 7%
0.0003
Низкий

7.8 High

CVSS3