Логотип exploitDog
bind:CVE-2023-39523
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-39523

Количество 3

Количество 3

nvd логотип

CVE-2023-39523

около 2 лет назад

ScanCode.io is a server to script and automate software composition analysis with ScanPipe pipelines. Prior to version 32.5.1, the software has a possible command injection vulnerability in the docker fetch process as it allows to append malicious commands in the `docker_reference` parameter. In the function `scanpipe/pipes/fetch.py:fetch_docker_image` the parameter `docker_reference` is user controllable. The `docker_reference` variable is then passed to the vulnerable function `get_docker_image_platform`. However, the `get_docker_image_plaform` function constructs a shell command with the passed `docker_reference`. The `pipes.run_command` then executes the shell command without any prior sanitization, making the function vulnerable to command injections. A malicious user who is able to create or add inputs to a project can inject commands. Although the command injections are blind and the user will not receive direct feedback without logs, it is still possible to cause damage to th

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-2ggp-cmvm-f62f

около 2 лет назад

ScanCode.io command injection in docker image fetch process

CVSS3: 6.8
EPSS: Низкий
fstec логотип

BDU:2023-04626

около 2 лет назад

Уязвимость функции fetch_docker_image() средства автоматизации процесса анализа программного обеспечения ScanCode.io, позволяющая нарушителю выполнить произвольные команды

CVSS3: 6.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-39523

ScanCode.io is a server to script and automate software composition analysis with ScanPipe pipelines. Prior to version 32.5.1, the software has a possible command injection vulnerability in the docker fetch process as it allows to append malicious commands in the `docker_reference` parameter. In the function `scanpipe/pipes/fetch.py:fetch_docker_image` the parameter `docker_reference` is user controllable. The `docker_reference` variable is then passed to the vulnerable function `get_docker_image_platform`. However, the `get_docker_image_plaform` function constructs a shell command with the passed `docker_reference`. The `pipes.run_command` then executes the shell command without any prior sanitization, making the function vulnerable to command injections. A malicious user who is able to create or add inputs to a project can inject commands. Although the command injections are blind and the user will not receive direct feedback without logs, it is still possible to cause damage to th

CVSS3: 6.8
2%
Низкий
около 2 лет назад
github логотип
GHSA-2ggp-cmvm-f62f

ScanCode.io command injection in docker image fetch process

CVSS3: 6.8
2%
Низкий
около 2 лет назад
fstec логотип
BDU:2023-04626

Уязвимость функции fetch_docker_image() средства автоматизации процесса анализа программного обеспечения ScanCode.io, позволяющая нарушителю выполнить произвольные команды

CVSS3: 6.8
2%
Низкий
около 2 лет назад

Уязвимостей на страницу