An issue in tiagorlampert CHAOS before 1b451cf62582295b7225caf5a7b506f0bad56f6b and 24c9e109b5be34df7b2bce8368eae669c481ed5e allows a remote attacker to execute arbitrary code via the unsafe concatenation of the `filename` argument into the `buildStr` string without any sanitization or filtering.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2024-05-07T00:00:00

Updated: 2024-08-02T02:27:53.700Z

Reserved: 2024-04-23T00:00:00

Link: CVE-2024-33434

cve-icon Vulnrichment

Updated: 2024-05-07T20:06:06.690Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-05-07T14:15:10.760

Modified: 2024-07-03T01:58:12.927

Link: CVE-2024-33434

cve-icon Redhat

No data.