Vulnerability Description
super-xray is a vulnerability scanner (xray) GUI launcher. In version 0.1-beta, the URL is not filtered and directly spliced into the command, resulting in a possible RCE vulnerability. Users should upgrade to super-xray 0.2-beta.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Super-Xray Project | Super-Xray | 0.1 |
Related Weaknesses (CWE)
References
- https://github.com/4ra1n/super-xray/releases/tag/0.2-betaRelease NotesThird Party Advisory
- https://github.com/4ra1n/super-xray/security/advisories/GHSA-732j-763p-cvqgExploitThird Party Advisory
- https://github.com/4ra1n/super-xray/releases/tag/0.2-betaRelease NotesThird Party Advisory
- https://github.com/4ra1n/super-xray/security/advisories/GHSA-732j-763p-cvqgExploitThird Party Advisory
FAQ
What is CVE-2022-41945?
CVE-2022-41945 is a vulnerability with a CVSS score of 6.5 (MEDIUM). super-xray is a vulnerability scanner (xray) GUI launcher. In version 0.1-beta, the URL is not filtered and directly spliced into the command, resulting in a possible RCE vulnerability. Users should...
How severe is CVE-2022-41945?
CVE-2022-41945 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-41945?
Check the references section above for vendor advisories and patch information. Affected products include: Super-Xray Project Super-Xray.