CVE-2020-17367
HIGHFirejail <0.9.62 - Command Injection
Title source: llmDescription
Firejail through 0.9.62 does not honor the -- end-of-options indicator after the --output option, which may lead to command injection.
References (8)
Scores
CVSS v3
7.8
EPSS
0.0014
EPSS Percentile
33.1%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-88
Status
published
Affected Products (6)
firejail_project/firejail
< 0.9.62
debian/debian_linux
fedoraproject/fedora
fedoraproject/fedora
debian/debian_linux
opensuse/leap
Timeline
Published
Aug 11, 2020
Tracked Since
Feb 18, 2026