9.8

CVE-2013-7378

scripts/email.coffee in the Hubot Scripts module before 2.4.4 for Node.js allows remote attackers to execute arbitrary commands.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Hubot Scripts ProjectHubot Scripts SwPlatformnode.js Version < 2.4.4
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.69% 0.839
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

http://www.openwall.com/lists/oss-security/2014/05/13/1
Third Party Advisory
Mailing List
http://www.openwall.com/lists/oss-security/2014/05/15/2
Third Party Advisory
Mailing List
https://github.com/github/hubot-scripts/commit/feee5abdb038a229a98969ae443cdb8a61747782
Patch
Third Party Advisory
https://web.archive.org/web/20140731222413/https://nodesecurity.io/advisories/Hubot_Potential_command_injection_in_email.coffee
Third Party Advisory