PT-2019-2577 · Xterm.Js · Xterm.Js

CVE-2019-0542

·

Publicado

2019-01-09

·

Atualizado

2022-10-27

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions xterm.js (affected versions not specified)
Description A remote code execution issue exists due to the mishandling of special characters by the xterm.js component. This can allow a remote attacker to execute arbitrary code. The vulnerability is related to the lack of input data sanitization. It was also discovered that this issue could be exploited in the AWS CloudShell service, potentially leading to remote code execution on EC2 servers accessed through the CloudShell console. The successful exploitation of this vulnerability could provide an attacker with a powerful entry point into the AWS infrastructure, including managed Kubernetes services like EKS and ESC.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Code Injection

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2019-02452
CVE-2019-0542
GHSA-MC23-976P-J42X
RHSA-2019:1422
RHSA-2019:2551
RHSA-2019:2552

Produtos afetados

Xterm.Js