An OS command injection vulnerability exists in web2py 2.24.1 and earlier. When the product is configured to use notifySendHandler for logging (not the default configuration), a crafted web request may execute an arbitrary OS command on the web server using the product.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 18 Sep 2024 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: jpcert
Published:
Updated: 2024-09-18T14:02:11.090Z
Reserved: 2023-10-04T23:39:17.361Z
Link: CVE-2023-45158
Updated: 2024-08-02T20:14:19.011Z
Status : Modified
Published: 2023-10-16T08:15:09.990
Modified: 2024-11-21T08:26:27.417
Link: CVE-2023-45158
No data.
OpenCVE Enrichment
No data.
Weaknesses