2024-12-08 03:06:42 +00:00

48 lines
2.0 KiB
JSON

{
"id": "CVE-2024-49400",
"sourceIdentifier": "cve-assign@fb.com",
"published": "2024-10-17T18:15:15.547",
"lastModified": "2024-11-01T19:35:28.673",
"vulnStatus": "Awaiting Analysis",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Tacquito prior to commit 07b49d1358e6ec0b5aa482fcd284f509191119e2 was not properly performing regex matches on authorized commands and arguments. Configured allowed commands/arguments were intended to require a match on the entire string, but instead only enforced a match on a sub-string. That would have potentially allowed unauthorized commands to be executed."
},
{
"lang": "es",
"value": "Antes de el commit 07b49d1358e6ec0b5aa482fcd284f509191119e2, Tacquito no realizaba correctamente las coincidencias de expresiones regulares en los comandos y argumentos autorizados. Los comandos y argumentos permitidos configurados ten\u00edan como objetivo exigir una coincidencia en toda la cadena, pero en su lugar solo aplicaban una coincidencia en una subcadena. Eso podr\u00eda haber permitido la ejecuci\u00f3n de comandos no autorizados."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "HIGH"
},
"exploitabilityScore": 3.9,
"impactScore": 5.9
}
]
},
"references": [
{
"url": "https://www.facebook.com/security/advisories/cve-2024-49400",
"source": "cve-assign@fb.com"
}
]
}