PT-2022-20044 · Pypi · Python-Libnmap

CVE-2022-30284

·

Published

2022-05-04

·

Updated

2024-08-03

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions python-libnmap versions through 0.7.2
Description Remote command execution can occur in the python-libnmap package if used in a client application that does not validate arguments. The vendor believes it would be unrealistic for an application to call NmapProcess with arguments taken from input data that arrived over an untrusted network.
Recommendations For versions through 0.7.2, consider validating arguments before calling NmapProcess to prevent remote command execution. As a temporary workaround, restrict the use of NmapProcess to trusted input data until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Argument Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-30284
GHSA-QWQV-J7JR-4HP6
PYSEC-2022-42999

Affected Products

Python-Libnmap