PT-2023-24606 · Brook · Brook

·

CVE-2023-33965

·

Publicado

2023-06-01

·

Atualizado

2023-06-09

CVSS v3.1

9.6

Crítica

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Brook versions prior to 20230606
Description The tproxy server in Brook is vulnerable to a drive-by command injection. An attacker can trick a victim into visiting a malicious web page, triggering requests to the local tproxy service and leading to remote code execution.
Recommendations For versions prior to 20230606, update to version 20230606 to resolve the issue. As a temporary workaround, consider restricting access to the tproxy server to minimize the risk of exploitation.

Exploit

Correção

OS Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-33965
GHSA-VFRJ-FV6P-3CPF

Produtos afetados

Brook