Lucene search

K
prionPRIOn knowledge basePRION:CVE-2021-45444
HistoryFeb 14, 2022 - 12:15 p.m.

Design/Logic Flaw

2022-02-1412:15:00
PRIOn knowledge base
www.prio-n.com
9

7.8 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

38.5%

In zsh before 5.8.1, an attacker can achieve code execution if they control a command output inside the prompt, as demonstrated by a %F argument. This occurs because of recursive PROMPT_SUBST expansion.