Improper Input Validation
Affecting bash package, versions <4.3-14ubuntu1.4
Report new vulnerabilities
Do your applications use this vulnerable package?
Test your applications
Overview
rbash in Bash before 4.4-beta2 did not prevent the shell user from modifying BASH_CMDS, thus allowing the user to execute any command with the permissions of the shell.
References
CVSS Score
7.8
low severity
-
Attack VectorLocal
-
Attack ComplexityLow
-
Privileges RequiredLow
-
User InteractionNone
-
ScopeUnchanged
-
ConfidentialityHigh
-
IntegrityHigh
-
AvailabilityHigh
- CVE
- CVE-2019-9924
- CWE
- CWE-20
- Snyk ID
- SNYK-UBUNTU1604-BASH-453533
- Disclosed
- 22 Mar, 2019
- Published
- 22 Mar, 2019