Improper Neutralization of Argument Delimiters in a Command in vcs - CVE-2022-21235
Published: January 31, 2023
Vulnerability identifier: #VU71700
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-21235
CWE-ID: CWE-88
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to argument strings being passed to hg in a way that additional flags can be set when hg is executed. A remote attacker can send a specially crafted request and execute arbitrary code on the target system.
Affected software
vcs
Cloud Pak for Security (CP4S)
Red Hat OpenShift Container Platform
Red Hat OpenStack
Cloud Pak for Security (CP4S)
Red Hat OpenShift Container Platform
Red Hat OpenStack
How to mitigate CVE-2022-21235
Install updates from vendor's website.
vcs - update to 1.13.3
Cloud Pak for Security (CP4S) - update to 1.10.7.0
Red Hat OpenShift Container Platform - update to 4.11.45
Red Hat OpenStack - update to 17.1
Cloud Pak for Security (CP4S) - update to 1.10.7.0
Red Hat OpenShift Container Platform - update to 4.11.45
Red Hat OpenStack - update to 17.1