CVE-2024-4748

The CRUDDIY project is vulnerable to shell command injection via sending a crafted POST request to the application server.  The exploitation risk is limited since CRUDDIY is meant to be launched locally. Nevertheless, a user with the project running on their computer might visit a website which would send such a malicious request to the locally launched server.
Configurations

Configuration 1 (hide)

cpe:2.3:a:j11g:cruddiy:*:*:*:*:*:*:*:*

History

21 Nov 2024, 09:43

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 7.8
v2 : unknown
v3 : 8.8
References () https://cert.pl/en/posts/2024/06/CVE-2024-4748 - Third Party Advisory () https://cert.pl/en/posts/2024/06/CVE-2024-4748 - Third Party Advisory
References () https://cert.pl/posts/2024/06/CVE-2024-4748 - Third Party Advisory () https://cert.pl/posts/2024/06/CVE-2024-4748 - Third Party Advisory
References () https://github.com/jan-vandenberg/cruddiy/issues/67 - Issue Tracking () https://github.com/jan-vandenberg/cruddiy/issues/67 - Issue Tracking

10 Oct 2024, 16:15

Type Values Removed Values Added
CWE CWE-77

26 Jun 2024, 14:07

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 8.8
v2 : unknown
v3 : 7.8
First Time J11g cruddiy
J11g
Summary
  • (es) El proyecto CRUDDIY es vulnerable a la inyección de comandos de shell mediante el envío de una solicitud POST manipulada al servidor de aplicaciones. El riesgo de explotación es limitado ya que CRUDDIY debe lanzarse localmente. Sin embargo, un usuario con el proyecto ejecutándose en su computadora podría visitar un sitio web que enviaría una solicitud maliciosa al servidor iniciado localmente.
CPE cpe:2.3:a:j11g:cruddiy:*:*:*:*:*:*:*:*
References () https://cert.pl/en/posts/2024/06/CVE-2024-4748 - () https://cert.pl/en/posts/2024/06/CVE-2024-4748 - Third Party Advisory
References () https://cert.pl/posts/2024/06/CVE-2024-4748 - () https://cert.pl/posts/2024/06/CVE-2024-4748 - Third Party Advisory
References () https://github.com/jan-vandenberg/cruddiy/issues/67 - () https://github.com/jan-vandenberg/cruddiy/issues/67 - Issue Tracking
CWE CWE-78

24 Jun 2024, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-24 14:15

Updated : 2024-11-21 09:43


NVD link : CVE-2024-4748

Mitre link : CVE-2024-4748

CVE.ORG link : CVE-2024-4748


JSON object : View

Products Affected

j11g

  • cruddiy
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')