Vulnerability Description
openITCOCKPIT before 3.7.3 has a web-based terminal that allows attackers to execute arbitrary OS commands via shell metacharacters that are mishandled on an su command line in app/Lib/SudoMessageInterface.php.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| It-Novum | Openitcockpit | < 3.7.3 |
Related Weaknesses (CWE)
References
- https://github.com/it-novum/openITCOCKPIT/commit/73b5b34afa8bd82ff26c00975583412Patch
- https://openitcockpit.io/2020/2020/03/23/openitcockpit-3-7-3-released/Vendor Advisory
- https://github.com/it-novum/openITCOCKPIT/commit/73b5b34afa8bd82ff26c00975583412Patch
- https://openitcockpit.io/2020/2020/03/23/openitcockpit-3-7-3-released/Vendor Advisory
FAQ
What is CVE-2020-10789?
CVE-2020-10789 is a vulnerability with a CVSS score of 9.8 (CRITICAL). openITCOCKPIT before 3.7.3 has a web-based terminal that allows attackers to execute arbitrary OS commands via shell metacharacters that are mishandled on an su command line in app/Lib/SudoMessageInte...
How severe is CVE-2020-10789?
CVE-2020-10789 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-10789?
Check the references section above for vendor advisories and patch information. Affected products include: It-Novum Openitcockpit.