Improper Neutralization of Argument Delimiters in a Command in XZ Utils - CVE-2024-47611
Published: April 3, 2025
Vulnerability details
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to improper validation of arguments passed via command line to the application. A remote attacker can pass specially crafted input to the application (e.g. using a command with Unicode characters in a filename) and execute arbitrary OS commands on the system.
Affected software
APEX Cloud Platform for Microsoft Azure
Storage Resource Manager
APEX Cloud Platform for Red Hat OpenShift
Dell EMC Storage Monitoring and Reporting (SMR)
How to mitigate CVE-2024-47611
APEX Cloud Platform for Microsoft Azure - update to 01.04.01.00
APEX Cloud Platform for Red Hat OpenShift - update to 03.04.01.00
Storage Resource Manager - update to 5.0.2.2
Dell EMC Storage Monitoring and Reporting (SMR) - update to 5.0.2.2
External References
Related Security Bulletins
- Argument injection in XZ Utils
- Dell APEX Cloud Platform for Microsoft Azure update for third-party components
- Dell APEX Cloud Platform for Red Hat OpenShift update for third-party components
- Multiple vulnerabilities in Dell Storage Resource Manager (SRM) and Dell Storage Monitoring and Reporting (SMR)