7.2
CVSSv2

CVE-2019-9924

Published: 22/03/2019 Updated: 05/04/2022
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 643
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

rbash in Bash prior to 4.4-beta2 did not prevent the shell user from modifying BASH_CMDS, thus allowing the user to execute any command with the permissions of the shell.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gnu bash

gnu bash 4.4

debian debian linux 8.0

opensuse leap 42.3

netapp hci management node -

netapp solidfire -

canonical ubuntu linux 12.04

canonical ubuntu linux 14.04

canonical ubuntu linux 16.04

Vendor Advisories

A system hardening measure could be bypassed ...
A system hardening measure could be bypassed ...
Synopsis Moderate: bash security update Type/Severity Security Advisory: Moderate Topic An update for bash is now available for Red Hat Enterprise Linux 74 Advanced Update Support, Red Hat Enterprise Linux 74 Telco Extended Update Support, and Red Hat Enterprise Linux 74 Update Services for SAP Solutions ...
Synopsis Moderate: bash security update Type/Severity Security Advisory: Moderate Topic An update for bash is now available for Red Hat Enterprise Linux 76 Extended Update SupportRed Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System ( ...
Synopsis Moderate: bash security update Type/Severity Security Advisory: Moderate Topic An update for bash is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) base score, which gi ...
Synopsis Moderate: bash security update Type/Severity Security Advisory: Moderate Topic An update for bash is now available for Red Hat Enterprise Linux 77 Extended Update SupportRed Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System ( ...
rbash in Bash before 44-beta2 did not prevent the shell user from modifying BASH_CMDS, thus allowing the user to execute any command with the permissions of the shell (CVE-2019-9924) ...
rbash in Bash before 44-beta2 did not prevent the shell user from modifying BASH_CMDS, thus allowing the user to execute any command with the permissions of the shell (CVE-2019-9924) ...
Impact: Moderate Public Date: 2019-03-07 CWE: CWE-732 Bugzilla: 1691774: CVE-2019-9924 bash: BASH_CMD i ...