CVE-2019-20807
MEDIUMVim < 8.1.0881 - OS Command Injection
Title source: ruleDescription
In Vim before 8.1.0881, users can circumvent the rvim restricted mode and execute arbitrary OS commands via scripting interfaces (e.g., Python, Ruby, or Lua).
Scores
CVSS v3
5.3
EPSS
0.0021
EPSS Percentile
42.6%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Classification
CWE
CWE-78
Status
published
Affected Products (9)
vim/vim
< 8.1.0881
debian/debian_linux
opensuse/leap
canonical/ubuntu_linux
canonical/ubuntu_linux
apple/mac_os_x
apple/mac_os_x
starwindsoftware/command_center
starwindsoftware/san_\&_nas
Timeline
Published
May 28, 2020
Tracked Since
Feb 18, 2026