find-exec is a utility to discover available shell commands. Versions prior to 1.0.3 did not properly escape user input and are vulnerable to Command Injection via an attacker controlled parameter. As a result, attackers may run malicious shell commands in the context of the running process. This issue has been addressed in version 1.0.3. users are advised to upgrade. Users unable to upgrade should ensure that all input passed to find-exec comes from a trusted source.
History

Tue, 01 Oct 2024 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2023-08-30T17:39:20.849Z

Updated: 2024-10-01T18:13:41.300Z

Reserved: 2023-08-16T18:24:02.391Z

Link: CVE-2023-40582

cve-icon Vulnrichment

Updated: 2024-08-02T18:38:50.852Z

cve-icon NVD

Status : Modified

Published: 2023-08-30T18:15:09.783

Modified: 2024-11-21T08:19:45.630

Link: CVE-2023-40582

cve-icon Redhat

No data.