mirror of
https://github.com/fkie-cad/nvd-json-data-feeds.git
synced 2025-05-28 09:11:28 +00:00
64 lines
2.0 KiB
JSON
64 lines
2.0 KiB
JSON
{
|
|
"id": "CVE-2024-6048",
|
|
"sourceIdentifier": "twcert@cert.org.tw",
|
|
"published": "2024-06-17T08:15:49.150",
|
|
"lastModified": "2024-06-17T12:42:04.623",
|
|
"vulnStatus": "Awaiting Analysis",
|
|
"cveTags": [],
|
|
"descriptions": [
|
|
{
|
|
"lang": "en",
|
|
"value": "Openfind's MailGates and MailAudit fail to properly filter user input when analyzing email attachments. An unauthenticated remote attacker can exploit this vulnerability to inject system commands and execute them on the remote server."
|
|
},
|
|
{
|
|
"lang": "es",
|
|
"value": "MailGates y MailAudit de Openfind no filtran adecuadamente la entrada del usuario al analizar los archivos adjuntos de correo electr\u00f3nico. Un atacante remoto no autenticado puede aprovechar esta vulnerabilidad para inyectar comandos del sistema y ejecutarlos en el servidor remoto."
|
|
}
|
|
],
|
|
"metrics": {
|
|
"cvssMetricV31": [
|
|
{
|
|
"source": "twcert@cert.org.tw",
|
|
"type": "Secondary",
|
|
"cvssData": {
|
|
"version": "3.1",
|
|
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
|
|
"attackVector": "NETWORK",
|
|
"attackComplexity": "LOW",
|
|
"privilegesRequired": "NONE",
|
|
"userInteraction": "NONE",
|
|
"scope": "UNCHANGED",
|
|
"confidentialityImpact": "HIGH",
|
|
"integrityImpact": "HIGH",
|
|
"availabilityImpact": "HIGH",
|
|
"baseScore": 9.8,
|
|
"baseSeverity": "CRITICAL"
|
|
},
|
|
"exploitabilityScore": 3.9,
|
|
"impactScore": 5.9
|
|
}
|
|
]
|
|
},
|
|
"weaknesses": [
|
|
{
|
|
"source": "twcert@cert.org.tw",
|
|
"type": "Primary",
|
|
"description": [
|
|
{
|
|
"lang": "en",
|
|
"value": "CWE-78"
|
|
}
|
|
]
|
|
}
|
|
],
|
|
"references": [
|
|
{
|
|
"url": "https://www.twcert.org.tw/en/cp-139-7886-20b61-2.html",
|
|
"source": "twcert@cert.org.tw"
|
|
},
|
|
{
|
|
"url": "https://www.twcert.org.tw/tw/cp-132-7885-a8013-1.html",
|
|
"source": "twcert@cert.org.tw"
|
|
}
|
|
]
|
|
} |