Описание
goose 1.37.0 executes arbitrary commands from recipe stdio extensions and retry.checks without security inspection. Attackers can distribute malicious recipes that execute shell commands as the user running goose, bypassing the recipe security scan which does not inspect extensions or retry configurations.
A flaw was found in goose. This vulnerability allows attackers to execute arbitrary commands by distributing malicious recipes that leverage insecure recipe standard input/output (stdio) extensions and retry checks. This bypasses the existing security scan, enabling the execution of shell commands with the privileges of the user running goose.
Отчет
Red Hat Enterprise Linux 9 and 10 and Fedora ship goose versions prior to 1.37.0 and are not affected by this vulnerability. The EPEL package ships a version in the affected range.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | goose | Not affected | ||
| Red Hat Enterprise Linux 9 | goose | Not affected |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
8.8 High
CVSS3
Связанные уязвимости
goose 1.37.0 executes arbitrary commands from recipe stdio extensions and retry.checks without security inspection. Attackers can distribute malicious recipes that execute shell commands as the user running goose, bypassing the recipe security scan which does not inspect extensions or retry configurations.
goose 1.37.0 executes arbitrary commands from recipe stdio extensions and retry.checks without security inspection. Attackers can distribute malicious recipes that execute shell commands as the user running goose, bypassing the recipe security scan which does not inspect extensions or retry configurations.
8.8 High
CVSS3