CVE-2019-1000018
PoC —CVSS 3.1
7.8 high
EPSS
2%p78
Published
()
Modified
Description
rssh version 2.3.4 contains a CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in allowscp permission that can result in Local command execution. This attack appear to be exploitable via An authorized SSH user with the allowscp permission.
- Vendors
- pizzashackdebianfedoraprojectcanonical
- Products
- rssh, debian linux, fedora, ubuntu linux
- Weakness
- CWE-77
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.