CRITICAL
Dropbox merou SSH Public Key public_key.py add_public_key injection
Published Dec 27, 2022
9.8
CRITICALCVSS 3.1
EPSS 0.67%
Description
A vulnerability was found in Dropbox merou. It has been classified as critical. Affected is the function add_public_key of the file grouper/public_key.py of the component SSH Public Key Handler. The manipulation of the argument public_key_str leads to injection. It is possible to launch the attack remotely. The name of the patch is d93087973afa26bc0a2d0a5eb5c0fde748bdd107. It is recommended to apply a patch to fix this issue. VDB-216906 is the identifier assigned to this vulnerability.
Affected products
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-52065 Advisory
- https://github.com/dropbox/merou/commit/d93087973afa26bc0a2d0a5eb5c0fde748bdd107 patchThird Party Advisory
- https://github.com/dropbox/merou/pull/673 issue-trackingPatchThird Party Advisory
- https://vuldb.com/?ctiid.216906 signaturepermissions-requiredThird Party Advisory
- https://vuldb.com/?id.216906 vdb-entrytechnical-descriptionThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-52065 | Advisory | |
| https://github.com/dropbox/merou/commit/d93087973afa26bc0a2d0a5eb5c0fde748bdd107 | patchThird Party Advisory | |
| https://github.com/dropbox/merou/pull/673 | issue-trackingPatchThird Party Advisory | |
| https://vuldb.com/?ctiid.216906 | signaturepermissions-requiredThird Party Advisory | |
| https://vuldb.com/?id.216906 | vdb-entrytechnical-descriptionThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Dec 27, 2022
Updated Aug 3, 2024
Reserved Dec 27, 2022
Link CVE-2022-4768
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2022-52065 Assigner VulDB
Published Dec 27, 2022
Updated Aug 3, 2024
Exploited since n/a
Link EUVD-2022-52065