CVE-2013-2095: Command Injection
Published Dec 10, 2019
·Updated
rubygem-openshift-origin-controller: API can be used to create applications via cartridgecache.rb URI.prase() to perform command injection
Affected Software
2 affected components
rubygems/openshift-origin-controller<=1.3.4
Openshift-origin-controller Project Openshift-origin-controller Ruby
Event History
Dec 10, 2019
CVE Published
via MITRE·01:21 PM
Data Sourced
via MITRE·01:21 PM
DescriptionWeakness
May 5, 2022
Advisory Published
12:29 AM
Frequently Asked Questions
1
What is the severity of CVE-2013-2095?
CVE-2013-2095 is classified as a critical vulnerability due to its potential for command injection.
2
How do I fix CVE-2013-2095?
To fix CVE-2013-2095, you should update the openshift-origin-controller package to version 1.3.5 or higher.
3
What versions of openshift-origin-controller are affected by CVE-2013-2095?
CVE-2013-2095 affects openshift-origin-controller versions up to and including 1.3.4.
4
Is CVE-2013-2095 exploitable remotely?
Yes, CVE-2013-2095 can be exploited remotely via the API to create applications.
5
What are the potential impacts of exploiting CVE-2013-2095?
Exploiting CVE-2013-2095 allows an attacker to execute arbitrary commands on the server running the affected software.