Lucene search

K
osvGoogleOSV:GHSA-5F2P-6VJV-2Q2M
HistoryMay 17, 2022 - 4:56 a.m.

Sup Code Injection vulnerability

2022-05-1704:56:46
Google
osv.dev
9
code injection
vulnerability
sup software
remote attackers
arbitrary commands
email attachment

EPSS

0.021

Percentile

89.4%

Sup before 0.13.2.1 and 0.14.x before 0.14.1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the filename of an email attachment.