find-exec is a utility to discover available shell commands. Versions prior to 1.0.3 did not properly escape user input and are vulnerable to Command Injection via an attacker controlled parameter. As a result, attackers may run malicious shell commands in the context of the running process. This issue has been addressed in version 1.0.3. users are advised to upgrade. Users unable to upgrade should ensure that all input passed to find-exec comes from a trusted source.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: GitHub_M

Published: 2023-08-30T17:39:20.849Z

Updated: 2023-08-30T17:39:20.849Z

Reserved: 2023-08-16T18:24:02.391Z


Link: CVE-2023-40582

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2023-08-30T18:15:09.783

Modified: 2023-09-05T12:57:14.317


Link: CVE-2023-40582

JSON object: View

cve-icon Redhat Information

No data.

CWE