← voltar
CVE-2020-15167

Arbitrary code execution via configuration file in Miller

CVSS 8.2 HIGHEPSS 0.4%CWE-94
Vexday Risk Score
21Baixo
Decisão SSVC (CISA)
Track
Sem sinal de exploração → monitorar
CVSS 8.2EPSS 0.4%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
02 set 2020Publicada no NVD
Recomendação: Monitorar — sem sinal de exploração no momento.
In Miller (command line utility) using the configuration file support introduced in version 5.9.0, it is possible for an attacker to cause Miller to run arbitrary code by placing a malicious `.mlrrc` file in the working directory. See linked GitHub Security Advisory for complete details. A fix is ready and will be released as Miller 5.9.1.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
Produtos afetados
johnkerl · miller