Description
acme.sh before 3.0.6 runs arbitrary commands from a remote server via eval, as exploited in the wild in June 2023.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-42020 | acme.sh before 3.0.6 runs arbitrary commands from a remote server via eval, as exploited in the wild in June 2023. |
References
History
Wed, 30 Oct 2024 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-94 | |
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-02-13T17:01:47.598Z
Reserved: 2023-07-13T00:00:00.000Z
Link: CVE-2023-38198
Updated: 2024-08-02T17:30:14.099Z
Status : Modified
Published: 2023-07-13T03:15:09.977
Modified: 2026-06-17T06:09:38.793
Link: CVE-2023-38198
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-94
Improper Control of Generation of Code ('Code Injection')
- NVD-CWE-noinfo
EUVD