7.5
CVSSv2

CVE-2020-17368

Published: 11/08/2020 Updated: 07/11/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Firejail up to and including 0.9.62 mishandles shell metacharacters during use of the --output or --output-stderr option, which may lead to command injection.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

firejail project firejail

debian debian linux 9.0

debian debian linux 10.0

fedoraproject fedora 31

fedoraproject fedora 32

opensuse leap 15.2

Vendor Advisories

Tim Starling discovered two vulnerabilities in firejail, a sandbox program to restrict the running environment of untrusted applications CVE-2020-17367 It was reported that firejail does not respect the end-of-options separator ("--"), allowing an attacker with control over the command line options of the sandboxed application, to wri ...