Логотип exploitDog
bind:CVE-2024-41815
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-41815

Количество 3

Количество 3

nvd логотип

CVE-2024-41815

больше 1 года назад

Starship is a cross-shell prompt. Starting in version 1.0.0 and prior to version 1.20.0, undocumented and unpredictable shell expansion and/or quoting rules make it easily to accidentally cause shell injection when using custom commands with starship in bash. This issue only affects users with custom commands, so the scope is limited, and without knowledge of others' commands, it could be hard to successfully target someone. Version 1.20.0 fixes the vulnerability.

CVSS3: 7.4
EPSS: Низкий
debian логотип

CVE-2024-41815

больше 1 года назад

Starship is a cross-shell prompt. Starting in version 1.0.0 and prior ...

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-vx24-x4mv-vwr5

больше 1 года назад

Starship vulnerable to shell injection via undocumented, unpredictable shell expansion in custom commands

CVSS3: 7.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-41815

Starship is a cross-shell prompt. Starting in version 1.0.0 and prior to version 1.20.0, undocumented and unpredictable shell expansion and/or quoting rules make it easily to accidentally cause shell injection when using custom commands with starship in bash. This issue only affects users with custom commands, so the scope is limited, and without knowledge of others' commands, it could be hard to successfully target someone. Version 1.20.0 fixes the vulnerability.

CVSS3: 7.4
0%
Низкий
больше 1 года назад
debian логотип
CVE-2024-41815

Starship is a cross-shell prompt. Starting in version 1.0.0 and prior ...

CVSS3: 7.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-vx24-x4mv-vwr5

Starship vulnerable to shell injection via undocumented, unpredictable shell expansion in custom commands

CVSS3: 7.4
0%
Низкий
больше 1 года назад

Уязвимостей на страницу