Логотип exploitDog
bind:CVE-2019-5029
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2019-5029

Количество 3

Количество 3

nvd логотип

CVE-2019-5029

около 6 лет назад

An exploitable command injection vulnerability exists in the Config editor of the Exhibitor Web UI versions 1.0.9 to 1.7.1. Arbitrary shell commands surrounded by backticks or $() can be inserted into the editor and will be executed by the Exhibitor process when it launches ZooKeeper. An attacker can execute any command as the user running the Exhibitor process.

CVSS3: 9.8
EPSS: Высокий
github логотип

GHSA-vq4h-pfrp-qjjj

больше 3 лет назад

An exploitable command injection vulnerability exists in the Config editor of the Exhibitor Web UI versions 1.0.9 to 1.7.1. Arbitrary shell commands surrounded by backticks or $() can be inserted into the editor and will be executed by the Exhibitor process when it launches ZooKeeper. An attacker can execute any command as the user running the Exhibitor process.

CVSS3: 9.8
EPSS: Высокий
fstec логотип

BDU:2019-04685

около 6 лет назад

Уязвимость веб-интерфейса службы Exhibitor для управления экземплярами сервера ZooKeeper, позволяющая нарушителю выполнить произвольные команды

CVSS3: 9.8
EPSS: Высокий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2019-5029

An exploitable command injection vulnerability exists in the Config editor of the Exhibitor Web UI versions 1.0.9 to 1.7.1. Arbitrary shell commands surrounded by backticks or $() can be inserted into the editor and will be executed by the Exhibitor process when it launches ZooKeeper. An attacker can execute any command as the user running the Exhibitor process.

CVSS3: 9.8
80%
Высокий
около 6 лет назад
github логотип
GHSA-vq4h-pfrp-qjjj

An exploitable command injection vulnerability exists in the Config editor of the Exhibitor Web UI versions 1.0.9 to 1.7.1. Arbitrary shell commands surrounded by backticks or $() can be inserted into the editor and will be executed by the Exhibitor process when it launches ZooKeeper. An attacker can execute any command as the user running the Exhibitor process.

CVSS3: 9.8
80%
Высокий
больше 3 лет назад
fstec логотип
BDU:2019-04685

Уязвимость веб-интерфейса службы Exhibitor для управления экземплярами сервера ZooKeeper, позволяющая нарушителю выполнить произвольные команды

CVSS3: 9.8
80%
Высокий
около 6 лет назад

Уязвимостей на страницу