OS Command Injection in go-getter - CVE-2022-26945

 

OS Command Injection in go-getter - CVE-2022-26945

Published: May 30, 2022


Vulnerability identifier: #VU63810
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-26945
CWE-ID: CWE-78
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary shell commands on the target system.

The vulnerability exists due to improper input validation. A remote attacker can pass specially crafted data to the application and execute arbitrary OS commands on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

go-getter
Red Hat OpenShift Container Platform
IBM Cloud Pak for Watson AIOps
Red Hat OpenStack

How to mitigate CVE-2022-26945

Install updates from vendor's website.

go-getter - addressed in versions 1.6.1, 2.1.0
Red Hat OpenShift Container Platform - addressed in versions 4.8.49, 4.8.51, 4.8.53, 4.9.47, 4.9.50, 4.9.51, 4.9.54, 4.10.30, 4.10.31, 4.10.36, 4.10.39, 4.11.0, 4.11.12, 4.13.0
IBM Cloud Pak for Watson AIOps - update to 4.4.0
Red Hat OpenStack - update to 16.2.z

External References

Related Security Bulletins