ZeroHour

CVE-2020-7606

PoC
CVSS 3.1
9.8 critical
EPSS
3%p85
Published
()
Modified
Description

docker-compose-remote-api through 0.1.4 allows execution of arbitrary commands. Within 'index.js' of the package, the function 'exec(serviceName, cmd, fnStdout, fnStderr, fnExit)' uses the variable 'serviceName' which can be controlled by users without any sanitization.

Vendors
docker-compose-remote-api project
Products
docker-compose-remote-api
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.