Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:44222
HistoryNov 10, 2023 - 6:58 a.m.

Command Injection

2023-11-1006:58:13
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
10
command injection
vulnerability
chromedriver
arbitrary commands
exploit

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

7.9 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

29.8%

chromedriver is vulnerable to Command Injection. This vulnerability allows an attacker to execute arbitrary commands on the host system by setting the chromedriver.path to an arbitrary system binary. The attacker could exploit this vulnerability by tricking a user into running a specially crafted ChromeDriver binary. The binary would contain a malicious command that would be executed when the user starts the ChromeDriver.

CPENameOperatorVersion
chromedriverle119.0.0
chromedriverle119.0.0

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

7.9 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

29.8%