Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-43799

Опубликовано: 10 сент. 2024
Источник: redhat
CVSS3: 5
EPSS Низкий

Описание

Send is a library for streaming files from the file system as a http response. Send passes untrusted user input to SendStream.redirect() which executes untrusted code. This issue is patched in send 0.19.0.

A flaw was found in the Send library. This vulnerability allows remote code execution via untrusted input passed to the SendStream.redirect() function.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Cryostat 3sendFix deferred
Logging Subsystem for Red Hat OpenShiftopenshift-logging/logging-view-plugin-rhel9Not affected
Migration Toolkit for Applications 7mta/mta-cli-rhel9Will not fix
Migration Toolkit for Applications 7mta/mta-ui-rhel9Will not fix
Migration Toolkit for RuntimessendWill not fix
Migration Toolkit for Virtualizationmigration-toolkit-virtualization/mtv-console-plugin-rhel9Not affected
Multicluster Engine for Kubernetesmulticluster-engine/console-mce-rhel8Not affected
Node HealthCheck Operatorworkload-availability/node-remediation-console-rhel8Will not fix
OpenShift Pipelinesopenshift-pipelines/pipelines-console-plugin-rhel8Will not fix
OpenShift Pipelinesopenshift-pipelines/pipelines-hub-api-rhel8Will not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=2311153send: Code Execution Vulnerability in Send Library

EPSS

Процентиль: 31%
0.00118
Низкий

5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5
ubuntu
больше 1 года назад

Send is a library for streaming files from the file system as a http response. Send passes untrusted user input to SendStream.redirect() which executes untrusted code. This issue is patched in send 0.19.0.

CVSS3: 5
nvd
больше 1 года назад

Send is a library for streaming files from the file system as a http response. Send passes untrusted user input to SendStream.redirect() which executes untrusted code. This issue is patched in send 0.19.0.

CVSS3: 4.7
msrc
около 1 года назад

send vulnerable to template injection that can lead to XSS

CVSS3: 5
debian
больше 1 года назад

Send is a library for streaming files from the file system as a http r ...

CVSS3: 5
github
больше 1 года назад

send vulnerable to template injection that can lead to XSS

EPSS

Процентиль: 31%
0.00118
Низкий

5 Medium

CVSS3