Improper Neutralization of Argument Delimiters in a Command in vcs - CVE-2022-21235

 

Improper Neutralization of Argument Delimiters in a Command in vcs - CVE-2022-21235

Published: January 31, 2023


Vulnerability identifier: #VU71700
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-21235
CWE-ID: CWE-88
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to argument strings being passed to hg in a way that additional flags can be set when hg is executed. A remote attacker can send a specially crafted request and execute arbitrary code on the target system.


Affected software

vcs
Cloud Pak for Security (CP4S)
Red Hat OpenShift Container Platform
Red Hat OpenStack

How to mitigate CVE-2022-21235

Install updates from vendor's website.

vcs - update to 1.13.3
Cloud Pak for Security (CP4S) - update to 1.10.7.0
Red Hat OpenShift Container Platform - update to 4.11.45
Red Hat OpenStack - update to 17.1

External References

Related Security Bulletins