Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:46684
HistoryApr 30, 2024 - 7:47 a.m.

Deserialization Of Untrusted Data

2024-04-3007:47:07
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
6
vulnerability
ops-cli
improper handling
user-supplied data
arbitrary code execution
deserialization

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.8

Confidence

High

EPSS

0.156

Percentile

96.0%

ops-cli is vulnerable to Deserialization Of Untrusted Data. The vulnerability is due to improper handling of user-supplied data in the checkout_repo function, which allows an attacker to execute arbitrary code on the victim’s machine.

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.8

Confidence

High

EPSS

0.156

Percentile

96.0%

Related for VERACODE:46684