88 lines
2.4 KiB
JSON
Raw Normal View History

2023-04-24 12:24:31 +02:00
{
"id": "CVE-2023-0164",
"sourceIdentifier": "help@fluidattacks.com",
"published": "2023-01-18T22:15:10.597",
"lastModified": "2023-01-28T03:37:57.693",
"vulnStatus": "Analyzed",
"descriptions": [
{
"lang": "en",
"value": "OrangeScrum version 2.0.11 allows an authenticated external attacker to execute arbitrary commands on the server. This is possible because the application injects an attacker-controlled parameter into a system function."
},
{
"lang": "es",
"value": "OrangeScrum versi\u00f3n 2.0.11 permite que un atacante externo autenticado ejecute comandos arbitrarios en el servidor. Esto es posible porque la aplicaci\u00f3n inyecta un par\u00e1metro controlado por el atacante en una funci\u00f3n del sistema."
2023-04-24 12:24:31 +02:00
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "LOW",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "HIGH",
"baseScore": 8.8,
"baseSeverity": "HIGH"
},
"exploitabilityScore": 2.8,
"impactScore": 5.9
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-78"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:orangescrum:orangescrum:2.0.11:*:*:*:*:*:*:*",
"matchCriteriaId": "563467F2-799D-404D-89D2-A6B5B6092614"
}
]
}
]
}
],
"references": [
{
"url": "https://fluidattacks.com/advisories/queen/",
"source": "help@fluidattacks.com",
"tags": [
"Exploit",
"Third Party Advisory"
]
},
{
"url": "https://github.com/Orangescrum/orangescrum",
"source": "help@fluidattacks.com",
"tags": [
"Product",
"Third Party Advisory"
]
}
]
}