Lucene search

K
nvd[email protected]NVD:CVE-2014-2888
HistoryApr 23, 2014 - 3:55 p.m.

CVE-2014-2888

2014-04-2315:55:04
web.nvd.nist.gov

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7.5 High

AI Score

Confidence

Low

0.024 Low

EPSS

Percentile

90.0%

lib/sfpagent/bsig.rb in the sfpagent gem before 0.4.15 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in the module name in a JSON request.

Affected configurations

NVD
Node
herrysfpagentRange0.4.14ruby
OR
herrysfpagentMatch0.0.1ruby
OR
herrysfpagentMatch0.1.0ruby
OR
herrysfpagentMatch0.1.1ruby
OR
herrysfpagentMatch0.1.2ruby
OR
herrysfpagentMatch0.1.3ruby
OR
herrysfpagentMatch0.1.4ruby
OR
herrysfpagentMatch0.1.5ruby
OR
herrysfpagentMatch0.1.6ruby
OR
herrysfpagentMatch0.1.7ruby
OR
herrysfpagentMatch0.1.8ruby
OR
herrysfpagentMatch0.1.9ruby
OR
herrysfpagentMatch0.1.10ruby
OR
herrysfpagentMatch0.1.11ruby
OR
herrysfpagentMatch0.1.12ruby
OR
herrysfpagentMatch0.1.13ruby
OR
herrysfpagentMatch0.1.14ruby
OR
herrysfpagentMatch0.2.0ruby
OR
herrysfpagentMatch0.2.1ruby
OR
herrysfpagentMatch0.2.2ruby
OR
herrysfpagentMatch0.2.3ruby
OR
herrysfpagentMatch0.2.4ruby
OR
herrysfpagentMatch0.2.5ruby
OR
herrysfpagentMatch0.2.6ruby
OR
herrysfpagentMatch0.2.7ruby
OR
herrysfpagentMatch0.2.8ruby
OR
herrysfpagentMatch0.2.9ruby
OR
herrysfpagentMatch0.2.10ruby
OR
herrysfpagentMatch0.3.0ruby
OR
herrysfpagentMatch0.3.1ruby
OR
herrysfpagentMatch0.3.2ruby
OR
herrysfpagentMatch0.3.3ruby
OR
herrysfpagentMatch0.3.4ruby
OR
herrysfpagentMatch0.3.5ruby
OR
herrysfpagentMatch0.3.6ruby
OR
herrysfpagentMatch0.3.7ruby
OR
herrysfpagentMatch0.3.8ruby
OR
herrysfpagentMatch0.3.9ruby
OR
herrysfpagentMatch0.3.10ruby
OR
herrysfpagentMatch0.4.0ruby
OR
herrysfpagentMatch0.4.1ruby
OR
herrysfpagentMatch0.4.2ruby
OR
herrysfpagentMatch0.4.3ruby
OR
herrysfpagentMatch0.4.4ruby
OR
herrysfpagentMatch0.4.5ruby
OR
herrysfpagentMatch0.4.6ruby
OR
herrysfpagentMatch0.4.7ruby
OR
herrysfpagentMatch0.4.8ruby
OR
herrysfpagentMatch0.4.9ruby
OR
herrysfpagentMatch0.4.10ruby
OR
herrysfpagentMatch0.4.11ruby
OR
herrysfpagentMatch0.4.12ruby
OR
herrysfpagentMatch0.4.13ruby

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7.5 High

AI Score

Confidence

Low

0.024 Low

EPSS

Percentile

90.0%