MEDIUM · 5.3

CVE-2019-20807

In Vim before 8.1.0881, users can circumvent the rvim restricted mode and execute arbitrary OS commands via scripting interfaces (e.g., Python, Ruby, or Lua).

Vulnerability Description

In Vim before 8.1.0881, users can circumvent the rvim restricted mode and execute arbitrary OS commands via scripting interfaces (e.g., Python, Ruby, or Lua).

CVSS Score

5.3

MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
LOW
Integrity
LOW
Availability
LOW

Affected Products

VendorProductVersions
VimVim< 8.1.0881
DebianDebian Linux9.0
OpensuseLeap15.1
CanonicalUbuntu Linux16.04
AppleMac Os X10.13.6
StarwindsoftwareCommand Center2
StarwindsoftwareSan \& Nas1.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-20807?

CVE-2019-20807 is a vulnerability with a CVSS score of 5.3 (MEDIUM). In Vim before 8.1.0881, users can circumvent the rvim restricted mode and execute arbitrary OS commands via scripting interfaces (e.g., Python, Ruby, or Lua).

How severe is CVE-2019-20807?

CVE-2019-20807 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-20807?

Check the references section above for vendor advisories and patch information. Affected products include: Vim Vim, Debian Debian Linux, Opensuse Leap, Canonical Ubuntu Linux, Apple Mac Os X.