CVE-2020-11016
CRITICALIntelMQ Manager 1.1.0-2.1.1 - Authenticated OS Command Injection via Inspect-tool Send Functionality
Title source: llmDescription
IntelMQ Manager from version 1.1.0 and before version 2.1.1 has a vulnerability where the backend incorrectly handled messages given by user-input in the "send" functionality of the Inspect-tool of the Monitor component. An attacker with access to the IntelMQ Manager could possibly use this issue to execute arbitrary code with the privileges of the webserver. Version 2.1.1 fixes the vulnerability.
References (4)
Core 4
Core References
Patch, Third Party Advisory x_refsource_confirm
https://github.com/certtools/intelmq-manager/security/advisories/GHSA-rrhh-rcgp-q2m2
Patch, Third Party Advisory x_refsource_misc
https://github.com/certtools/intelmq-manager/commit/b9a2ac43a4f99d764b827108f6a99dc4a9faa013
Third Party Advisory x_refsource_misc
https://github.com/certtools/intelmq-manager/releases/tag/2.1.1
Third Party Advisory x_refsource_misc
https://lists.cert.at/pipermail/intelmq-users/2020-April/000161.html
Scores
CVSS v3
9.1
EPSS
0.0233
EPSS Percentile
81.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:L
Details
CWE
CWE-78
Status
published
Products (1)
intelmq_manager_project/intelmq_manager
1.1.0 - 2.1.1
Published
Apr 30, 2020
Tracked Since
Feb 18, 2026