"value":"A vulnerability in Imperative framework which allows already-privileged local actors to execute arbitrary shell commands via plugin install/update commands, or maliciously formed environment variables. Impacts Zowe CLI."
}
]
},
"problemtype":{
"problemtype_data":[
{
"description":[
{
"lang":"eng",
"value":"n/a"
}
]
}
]
},
"affects":{
"vendor":{
"vendor_data":[
{
"vendor_name":"Open Mainframe Project",
"product":{
"product_data":[
{
"product_name":"Zowe",
"version":{
"version_data":[
{
"version_affected":"<",
"version_name":"1.16.0",
"version_value":"1.28.2"
},
{
"version_affected":"<",
"version_name":"2.0.0",
"version_value":"2.5.0"
}
]
}
}
]
}
}
]
}
},
"references":{
"reference_data":[
{
"url":"https://github.com/zowe/imperative/",
"refsource":"MISC",
"name":"https://github.com/zowe/imperative/"
}
]
},
"exploit":[
{
"lang":"en",
"value":"There are no known exploits of this issue."
}
],
"solution":[
{
"lang":"en",
"value":"This issue is fixed in Zowe 1.28.2 or later, and Zowe 2.5.0 or later."