Vulnerability Description
Awesome spawn contains OS command injection vulnerability, which allows execution of additional commands passed to Awesome spawn as arguments. If untrusted input was included in command arguments, attacker could use this flaw to execute arbitrary command.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Manageiq | Awesomespawn | >= 1.2.0, < 1.5.0 |
Related Weaknesses (CWE)
References
- https://github.com/ManageIQ/awesome_spawn/commit/e524f85f1c6e292ef7d117d78185213PatchThird Party Advisory
- https://rubysec.com/advisories/CVE-2014-0156/Third Party Advisory
- https://github.com/ManageIQ/awesome_spawn/commit/e524f85f1c6e292ef7d117d78185213PatchThird Party Advisory
- https://rubysec.com/advisories/CVE-2014-0156/Third Party Advisory
FAQ
What is CVE-2014-0156?
CVE-2014-0156 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Awesome spawn contains OS command injection vulnerability, which allows execution of additional commands passed to Awesome spawn as arguments. If untrusted input was included in command arguments, att...
How severe is CVE-2014-0156?
CVE-2014-0156 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2014-0156?
Check the references section above for vendor advisories and patch information. Affected products include: Manageiq Awesomespawn.