8

CVE-2021-23556

Exploit

Exposed Dangerous Method or Function

The package guake before 3.8.5 are vulnerable to Exposed Dangerous Method or Function due to the exposure of execute_command and execute_command_by_uuid methods via the d-bus interface, which makes it possible for a malicious user to run an arbitrary command via the d-bus method. **Note:** Exploitation requires the user to have installed another malicious program that will be able to send dbus signals or run terminal commands.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Guake-projectGuake Version < 3.8.5
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.11% 0.617
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8 2.1 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
nvd@nist.gov 6 6.8 6.4
AV:N/AC:M/Au:S/C:P/I:P/A:P
report@snyk.io 6.4 1.6 4.7
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:L
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://github.com/Guake/guake/issues/1796
Third Party Advisory
Exploit
Issue Tracking
https://github.com/Guake/guake/pull/2017
Patch
Third Party Advisory
Issue Tracking
https://github.com/Guake/guake/pull/2017/commits/e3d671120bfe7ba28f50e256cc5e8a629781b888
Patch
Third Party Advisory
https://github.com/Guake/guake/releases
Third Party Advisory
Release Notes
https://snyk.io/vuln/SNYK-PYTHON-GUAKE-2386334
Patch
Third Party Advisory
Exploit
Issue Tracking