CVE-2024-49400

Tacquito prior to commit 07b49d1358e6ec0b5aa482fcd284f509191119e2 was not properly performing regex matches on authorized commands and arguments. Configured allowed commands/arguments were intended to require a match on the entire string, but instead only enforced a match on a sub-string. That would have potentially allowed unauthorized commands to be executed.
Configurations

No configuration.

History

01 Nov 2024, 19:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

18 Oct 2024, 12:52

Type Values Removed Values Added
Summary
  • (es) Antes de el commit 07b49d1358e6ec0b5aa482fcd284f509191119e2, Tacquito no realizaba correctamente las coincidencias de expresiones regulares en los comandos y argumentos autorizados. Los comandos y argumentos permitidos configurados tenían como objetivo exigir una coincidencia en toda la cadena, pero en su lugar solo aplicaban una coincidencia en una subcadena. Eso podría haber permitido la ejecución de comandos no autorizados.

17 Oct 2024, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-17 18:15

Updated : 2024-11-01 19:35


NVD link : CVE-2024-49400

Mitre link : CVE-2024-49400

CVE.ORG link : CVE-2024-49400


JSON object : View

Products Affected

No product.

CWE

No CWE.