Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2024-8517

Опубликовано: 06 сент. 2024
Источник: ubuntu
Приоритет: medium
EPSS Критический
CVSS3: 9.8

Описание

SPIP before 4.3.2, 4.2.16, and 4.1.18 is vulnerable to a command injection issue. A remote and unauthenticated attacker can execute arbitrary operating system commands by sending a crafted multipart file upload HTTP request.

РелизСтатусПримечание
devel

not-affected

4.3.8+dfsg-1
esm-apps/bionic

released

3.1.4-4~deb9u5ubuntu0.1~esm2
esm-apps/focal

released

3.2.7-1ubuntu0.1+esm2
esm-apps/jammy

needed

esm-apps/noble

needed

esm-apps/xenial

needed

focal

ignored

end of standard support, was needed
jammy

needed

noble

needed

oracular

released

4.3.1+dfsg-1ubuntu0.1

Показывать по

EPSS

Процентиль: 100%
0.93228
Критический

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
nvd
больше 1 года назад

SPIP before 4.3.2, 4.2.16, and 4.1.18 is vulnerable to a command injection issue. A remote and unauthenticated attacker can execute arbitrary operating system commands by sending a crafted multipart file upload HTTP request.

CVSS3: 9.8
debian
больше 1 года назад

SPIP before 4.3.2, 4.2.16, and 4.1.18 is vulnerable to a command inje ...

CVSS3: 9.8
github
больше 1 года назад

SPIP before 4.3.2, 4.2.16, and 4.1.18 is vulnerable to a command injection issue. A remote and unauthenticated attacker can execute arbitrary operating system commands by sending a crafted multipart file upload HTTP request.

EPSS

Процентиль: 100%
0.93228
Критический

9.8 Critical

CVSS3