Tacquito prior to commit 07b49d1358e6ec0b5aa482fcd284f509191119e2 was not properly performing regex matches on authorized commands and arguments. Configured allowed commands/arguments were intended to require a match on the entire string, but instead only enforced a match on a sub-string. That would have potentially allowed unauthorized commands to be executed.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Sun, 13 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.0019}

epss

{'score': 0.00212}


Fri, 01 Nov 2024 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Facebook
Facebook tacquito
CPEs cpe:2.3:a:facebook:tacquito:*:*:*:*:*:*:*:*
Vendors & Products Facebook
Facebook tacquito
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Oct 2024 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Oct 2024 17:30:00 +0000

Type Values Removed Values Added
Description Tacquito prior to commit 07b49d1358e6ec0b5aa482fcd284f509191119e2 was not properly performing regex matches on authorized commands and arguments. Configured allowed commands/arguments were intended to require a match on the entire string, but instead only enforced a match on a sub-string. That would have potentially allowed unauthorized commands to be executed.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: facebook

Published:

Updated: 2024-11-01T18:35:40.761Z

Reserved: 2024-10-15T01:05:31.784Z

Link: CVE-2024-49400

cve-icon Vulnrichment

Updated: 2024-10-17T20:44:09.879Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-10-17T18:15:15.547

Modified: 2024-11-01T19:35:28.673

Link: CVE-2024-49400

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.