Vulnerability Description
PHKP including commit 88fd9cfdf14ea4b6ac3e3967feea7bcaabb6f03b is affected by: Improper Neutralization of Special Elements used in a Command ('Command Injection'). The impact is: It is possible to manipulate gpg-keys or execute commands remotely. The component is: function pgp_exec() phkp.php:98. The attack vector is: HKP-Api: /pks/lookup?search.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Phkp Project | Phkp | - |
Related Weaknesses (CWE)
References
- https://github.com/remko/phkp/issues/1Third Party Advisory
- https://github.com/remko/phkp/issues/1Third Party Advisory
FAQ
What is CVE-2019-1010179?
CVE-2019-1010179 is a vulnerability with a CVSS score of 9.8 (CRITICAL). PHKP including commit 88fd9cfdf14ea4b6ac3e3967feea7bcaabb6f03b is affected by: Improper Neutralization of Special Elements used in a Command ('Command Injection'). The impact is: It is possible to man...
How severe is CVE-2019-1010179?
CVE-2019-1010179 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-1010179?
Check the references section above for vendor advisories and patch information. Affected products include: Phkp Project Phkp.