Description
A vulnerability in Imperative framework which allows already-privileged local actors to execute arbitrary shell commands via plugin install/update commands, or maliciously formed environment variables. Impacts Zowe CLI.
No analysis available yet.
Remediation
Vendor Solution
This issue is fixed in Zowe 1.28.2 or later, and Zowe 2.5.0 or later.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-0909 | A vulnerability in Imperative framework which allows already-privileged local actors to execute arbitrary shell commands via plugin install/update commands, or maliciously formed environment variables. Impacts Zowe CLI. |
Github GHSA |
GHSA-6q8m-42qq-64r7 | Imperative CLI vulnerable to Command Injection |
References
| Link | Providers |
|---|---|
| https://github.com/zowe/imperative/ |
|
History
No history.
Status: PUBLISHED
Assigner: Zowe
Published:
Updated: 2024-08-03T17:23:10.539Z
Reserved: 2023-02-22T15:14:11.344Z
Link: CVE-2021-4326
No data.
Status : Modified
Published: 2023-03-01T08:15:10.187
Modified: 2024-11-21T06:37:25.517
Link: CVE-2021-4326
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA