CVE-2023-38692

CloudExplorer Lite is an open source, lightweight cloud management platform. Versions prior to 1.3.1 contain a command injection vulnerability in the installation function in module management. The vulnerability has been fixed in v1.3.1. There are no known workarounds aside from upgrading.
Configurations

Configuration 1 (hide)

cpe:2.3:a:fit2cloud:cloudexplorer_lite:*:*:*:*:*:*:*:*

History

21 Nov 2024, 08:14

Type Values Removed Values Added
Summary
  • (es) CloudExplorer Lite es una plataforma de gestión de nubes ligera y de código abierto. Las versiones anteriores a la 1.3.1 contienen una vulnerabilidad de inyección de comandos en la función de instalación en la gestión de módulos. La vulnerabilidad se ha corregido en la versión 1.3.1. No hay soluciones conocidas aparte de la actualización.
References () https://github.com/CloudExplorer-Dev/CloudExplorer-Lite/blob/v1.3.0/framework/management-center/backend/src/main/java/com/fit2cloud/controller/ModuleManageController.java - Product () https://github.com/CloudExplorer-Dev/CloudExplorer-Lite/blob/v1.3.0/framework/management-center/backend/src/main/java/com/fit2cloud/controller/ModuleManageController.java - Product
References () https://github.com/CloudExplorer-Dev/CloudExplorer-Lite/releases/tag/v1.3.1 - Release Notes () https://github.com/CloudExplorer-Dev/CloudExplorer-Lite/releases/tag/v1.3.1 - Release Notes
References () https://github.com/CloudExplorer-Dev/CloudExplorer-Lite/security/advisories/GHSA-7wrc-f42m-9v5w - Exploit, Third Party Advisory () https://github.com/CloudExplorer-Dev/CloudExplorer-Lite/security/advisories/GHSA-7wrc-f42m-9v5w - Exploit, Third Party Advisory

09 Aug 2023, 13:19

Type Values Removed Values Added
References (MISC) https://github.com/CloudExplorer-Dev/CloudExplorer-Lite/blob/v1.3.0/framework/management-center/backend/src/main/java/com/fit2cloud/controller/ModuleManageController.java - (MISC) https://github.com/CloudExplorer-Dev/CloudExplorer-Lite/blob/v1.3.0/framework/management-center/backend/src/main/java/com/fit2cloud/controller/ModuleManageController.java - Product
References (MISC) https://github.com/CloudExplorer-Dev/CloudExplorer-Lite/security/advisories/GHSA-7wrc-f42m-9v5w - (MISC) https://github.com/CloudExplorer-Dev/CloudExplorer-Lite/security/advisories/GHSA-7wrc-f42m-9v5w - Exploit, Third Party Advisory
References (MISC) https://github.com/CloudExplorer-Dev/CloudExplorer-Lite/releases/tag/v1.3.1 - (MISC) https://github.com/CloudExplorer-Dev/CloudExplorer-Lite/releases/tag/v1.3.1 - Release Notes
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CPE cpe:2.3:a:fit2cloud:cloudexplorer_lite:*:*:*:*:*:*:*:*

04 Aug 2023, 18:53

Type Values Removed Values Added
New CVE

Information

Published : 2023-08-04 18:15

Updated : 2024-11-21 08:14


NVD link : CVE-2023-38692

Mitre link : CVE-2023-38692

CVE.ORG link : CVE-2023-38692


JSON object : View

Products Affected

fit2cloud

  • cloudexplorer_lite
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')