Описание
Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers to pass arbitrary OS commands from an unprivileged account.
A flaw was found in Pallets Click. This command injection vulnerability, located in the click.edit() function, allows an attacker with an unprivileged account to execute arbitrary operating system (OS) commands. This could lead to unauthorized control over the affected system.
Отчет
A command injection vulnerability exists in the click.edit() function of the Pallets Click library. The filename parameter is not sanitized before being interpolated into a shell command string, allowing an attacker who controls the filename to inject and execute arbitrary OS commands. The root cause is in edit_files(), which wraps the filename in double quotes and passes the resulting string to subprocess.Popen() with shell=True. A filename containing a double-quote character (") can break out of the quoting context and introduce arbitrary shell metacharacters.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Ansible Automation Platform 2 | python3.11-click | Not affected | ||
| Red Hat Ansible Automation Platform 2 | python3x-click | Not affected | ||
| Red Hat Ansible Automation Platform 2.5 for RHEL 8 | python3.12-click | Fixed | RHSA-2026:24761 | 09.06.2026 |
| Red Hat Ansible Automation Platform 2.5 for RHEL 9 | python3.12-click | Fixed | RHSA-2026:24761 | 09.06.2026 |
| Red Hat Ansible Automation Platform 2.6 for RHEL 10 | python-click | Fixed | RHSA-2026:24762 | 09.06.2026 |
| Red Hat Ansible Automation Platform 2.6 for RHEL 9 | python3.12-click | Fixed | RHSA-2026:24762 | 09.06.2026 |
Показывать по
Дополнительная информация
Статус:
EPSS
7.2 High
CVSS3
Связанные уязвимости
Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers to pass arbitrary OS commands from an unprivileged account.
Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers to pass arbitrary OS commands from an unprivileged account.
Pallets Click contains a command injection via Unsanitized Filename "click.edit()"
Pallets Click, versions 8.3.2 and below, contain a command injection v ...
EPSS
7.2 High
CVSS3