Описание
Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers to pass arbitrary OS commands from an unprivileged account.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | 8.2.0+0.really.8.1.8-1build1 |
| esm-apps-legacy/xenial | not-affected | |
| esm-apps/xenial | not-affected | |
| esm-infra/bionic | not-affected | |
| esm-infra/focal | not-affected | |
| jammy | not-affected | 8.0.3-1 |
| noble | not-affected | 8.1.6-2 |
| questing | not-affected | 8.2.0+0.really.8.1.8-1 |
| resolute | not-affected | 8.2.0+0.really.8.1.8-1build1 |
| upstream | needs-triage |
Показывать по
EPSS
7.2 High
CVSS3
Связанные уязвимости
Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers to pass arbitrary OS commands from an unprivileged account.
Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers to pass arbitrary OS commands from an unprivileged account.
Pallets Click contains a command injection via Unsanitized Filename "click.edit()"
Pallets Click, versions 8.3.2 and below, contain a command injection v ...
EPSS
7.2 High
CVSS3