Description

exec.CommandContext in Chaosblade 0.3 through 1.7.3, when server mode is used, allows OS command execution via the cmd parameter without authentication.

INFO

Published Date :

2024-09-18T00:00:00.000Z

Last Modified :

2024-09-18T18:18:37.401Z

Source :

mitre
AFFECTED PRODUCTS

The following products are affected by CVE-2023-47105 vulnerability.

Vendors Products
Chaosblade
  • Chaosblade

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact