Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:35474
HistoryMay 11, 2022 - 10:47 a.m.

OS Command Injection

2022-05-1110:47:23
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
49

0.106 Low

EPSS

Percentile

95.1%

openssl is vulnerable to OS command injection. The c_rehash script does not properly sanitise shell metacharacters to prevent command injection which allows an attacker to execute arbitrary commands with the privileges of the script.

References