CRITICAL
Slanger 0.6.0 is affected by: Remote Code Execution (RCE)
Published Jul 15, 2019
9.8
CRITICALCVSS 3.0
EPSS 4.04%
Description
Slanger 0.6.0 is affected by: Remote Code Execution (RCE). The impact is: A remote attacker can execute arbitrary commands by sending a crafted request to the server. The component is: Message handler & request validator. The attack vector is: Remote unauthenticated. The fixed version is: after commit 5267b455caeb2e055cccf0d2b6a22727c111f5c3.
Affected products
-
- Version 0.6.0 [fixed: after commit 5267b455caeb2e055cccf0d2b6a22727c111f5c3]StatusaffectedConstraints-
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (5)
- https://github.com/advisories/GHSA-rg32-m3hf-772v Advisory
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/slanger/CVE-2019-1010306.yml
- https://github.com/stevegraham/slanger/pull/238
- https://github.com/stevegraham/slanger/pull/238/commits/5267b455caeb2e055cccf0d2b6a22727c111f5c3 x_refsource_MISCPatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-1010306
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner dwf
Published Jul 15, 2019
Updated Aug 5, 2024
Reserved Mar 20, 2019
Link CVE-2019-1010306
CISA Vulnrichment
GHSA-RG32-M3HF-772V Updated n/a