PT-2018-16203 · Egg · Egg-Scripts

·

CVE-2018-3786

·

Published

2018-08-24

·

Updated

2023-02-02

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions egg-scripts versions prior to 2.8.1
Description A command injection issue allows arbitrary shell command execution through a maliciously crafted command line argument. This is only exploitable if a malicious argument is provided on the command line. For example, an attacker could use the eggctl start --daemon --stderr command with a malicious stderr argument, such as '/tmp/eggctl stderr.log; touch /tmp/malicious', to execute arbitrary shell commands.
Recommendations Update to version 2.8.1 or later.

Exploit

Fix

Command Injection

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-3786
GHSA-C9J3-WQPH-5XX9

Affected Products

Egg-Scripts