find-exec is a utility to discover available shell commands. Versions prior to 1.0.3 did not properly escape user input and are vulnerable to Command Injection via an attacker controlled parameter. As a result, attackers may run malicious shell commands in the context of the running process. This issue has been addressed in version 1.0.3. users are advised to upgrade. Users unable to upgrade should ensure that all input passed to find-exec comes from a trusted source.
Advisories
Source ID Title
EUVD EUVD EUVD-2023-2252 find-exec is a utility to discover available shell commands. Versions prior to 1.0.3 did not properly escape user input and are vulnerable to Command Injection via an attacker controlled parameter. As a result, attackers may run malicious shell commands in the context of the running process. This issue has been addressed in version 1.0.3. users are advised to upgrade. Users unable to upgrade should ensure that all input passed to find-exec comes from a trusted source.
Github GHSA Github GHSA GHSA-95rp-6gqp-6622 Command Injection Vulnerability in find-exec
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 01 Oct 2024 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-10-01T18:13:41.300Z

Reserved: 2023-08-16T18:24:02.391Z

Link: CVE-2023-40582

cve-icon Vulnrichment

Updated: 2024-08-02T18:38:50.852Z

cve-icon NVD

Status : Modified

Published: 2023-08-30T18:15:09.783

Modified: 2024-11-21T08:19:45.630

Link: CVE-2023-40582

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses