An issue was discovered in Object... CVE-2022-44794

- AV AC AU C I A
发布: 2022-11-07
修订: 2024-11-21

An issue was discovered in Object First Ootbi BETA build 1.0.7.712. Management protocol has a flow which allows a remote attacker to execute arbitrary Bash code with root privileges. The command that sets the hostname doesn't validate input parameters. As a result, arbitrary data goes directly to the Bash interpreter. An attacker would need credentials to exploit this vulnerability. This is fixed in Object First Ootbi BETA build 1.0.13.1611.

0%
暂无可用Exp或PoC
当前有1条受影响产品信息