10
CVSSv2

CVE-2014-3496

Published: 20/06/2014 Updated: 13/02/2023
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

cartridge_repository.rb in OpenShift Origin and Enterprise 1.2.8 up to and including 2.1.1 allows remote malicious users to execute arbitrary commands via shell metacharacters in a Source-Url ending with a (1) .tar.gz, (2) .zip, (3) .tgz, or (4) .tar file extension in a cartridge manifest file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat openshift origin 2.1

redhat openshift 2.0.6

redhat openshift 2.1

redhat openshift origin 2.1.1

redhat openshift 2.0.5

redhat openshift 2.0.2

redhat openshift origin 1.2.8

redhat openshift 2.1.1

redhat openshift 2.0.1

redhat openshift 2.0.3

redhat openshift 2.0.4

redhat openshift 1.2.8

redhat openshift 2.0

Vendor Advisories

cartridge_repositoryrb in OpenShift Origin and Enterprise 128 through 211 allows remote attackers to execute arbitrary commands via shell metacharacters in a Source-Url ending with a (1) targz, (2) zip, (3) tgz, or (4) tar file extension in a cartridge manifest file ...