Nette versions before 2.0.19, 2.1.13, 2.2.10, 2.3.14, 2.4.16, 3.0.6 are vulnerable to an code injection attack by passing specially formed parameters to URL that may possibly leading to RCE. Nette is a PHP/Composer MVC Framework.
References
Link | Resource |
---|---|
https://github.com/nette/application/security/advisories/GHSA-8gv3-3j7f-wg94 | Third Party Advisory |
https://lists.debian.org/debian-lts-announce/2021/04/msg00003.html | Mailing List Third Party Advisory |
https://packagist.org/packages/nette/application | Third Party Advisory |
https://packagist.org/packages/nette/nette | Third Party Advisory |
https://github.com/nette/application/security/advisories/GHSA-8gv3-3j7f-wg94 | Third Party Advisory |
https://lists.debian.org/debian-lts-announce/2021/04/msg00003.html | Mailing List Third Party Advisory |
https://packagist.org/packages/nette/application | Third Party Advisory |
https://packagist.org/packages/nette/nette | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
21 Nov 2024, 05:05
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : 7.5
v3 : 8.7 |
References | () https://github.com/nette/application/security/advisories/GHSA-8gv3-3j7f-wg94 - Third Party Advisory | |
References | () https://lists.debian.org/debian-lts-announce/2021/04/msg00003.html - Mailing List, Third Party Advisory | |
References | () https://packagist.org/packages/nette/application - Third Party Advisory | |
References | () https://packagist.org/packages/nette/nette - Third Party Advisory |
Information
Published : 2020-10-01 19:15
Updated : 2024-11-21 05:05
NVD link : CVE-2020-15227
Mitre link : CVE-2020-15227
CVE.ORG link : CVE-2020-15227
JSON object : View
Products Affected
nette
- application
debian
- debian_linux