Description
find-exec is a utility to discover available shell commands. Versions prior to 1.0.3 did not properly escape user input and are vulnerable to Command Injection via an attacker controlled parameter. As a result, attackers may run malicious shell commands in the context of the running process. This issue has been addressed in version 1.0.3. users are advised to upgrade. Users unable to upgrade should ensure that all input passed to find-exec comes from a trusted source.
Published: 2023-08-30
Score: 9.8 Critical
EPSS: 6.8% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-2252 find-exec is a utility to discover available shell commands. Versions prior to 1.0.3 did not properly escape user input and are vulnerable to Command Injection via an attacker controlled parameter. As a result, attackers may run malicious shell commands in the context of the running process. This issue has been addressed in version 1.0.3. users are advised to upgrade. Users unable to upgrade should ensure that all input passed to find-exec comes from a trusted source.
Github GHSA Github GHSA GHSA-95rp-6gqp-6622 Command Injection Vulnerability in find-exec
History

Tue, 01 Oct 2024 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Find-exec Project Find-exec
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-10-01T18:13:41.300Z

Reserved: 2023-08-16T18:24:02.391Z

Link: CVE-2023-40582

cve-icon Vulnrichment

Updated: 2024-08-02T18:38:50.852Z

cve-icon NVD

Status : Modified

Published: 2023-08-30T18:15:09.783

Modified: 2024-11-21T08:19:45.630

Link: CVE-2023-40582

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses