Impact
The vulnerability allows an attacker to inject arbitrary operating system commands by creating a file with a special filename inside the directory that the Black Duck package manager scans. Because the package manager concatenates discovered filesystem paths directly into shell command strings without quoting or escaping, metacharacters in the file name are interpreted by the shell, enabling command execution as the scan user.
Affected Systems
Black Duck’s blackduck-c-cpp package manager is affected in all releases before version 3.0.7. Any installation that has not yet upgraded to 3.0.7 or later is susceptible.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity, and the vulnerability is not listed in CISA KEV. EPSS information is not available. Exploitation requires only write access to the build directory used during scanning; no special permissions or configuration changes are needed. The attack vector is therefore local to the system or application that provides write access to the scanned directory, and it results in arbitrary command execution under the account that runs the scan.
OpenCVE Enrichment