PT-2014-5409 · Google+2 · Luci+2
CVE-2014-3593
·
Publicado
2014-10-14
·
Atualizado
2023-02-13
CVSS v2.0
6.0
Média
| Vetor | AV:N/AC:M/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
luci version 0.26.0
Description
The issue allows remote authenticated users with certain permissions to execute arbitrary Python code via a crafted cluster configuration.
Recommendations
For luci version 0.26.0, update to a version that fixes the eval injection issue to prevent arbitrary Python code execution.
Correção
Code Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Centos
Red Hat
Luci