CVE-2014-3593: Code Injection
Published Jul 26, 2013
·Updated
Eval injection vulnerability in luci 0.26.0 allows remote authenticated users with certain permissions to execute arbitrary Python code via a crafted cluster configuration.
Affected Software
1 affected component
Scientificlinux Luci=0.26.0
Event History
Jul 26, 2013
Data Sourced
via Red Hat·09:42 PM
DescriptionSeverityAffected Software
Oct 15, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-3593?
CVE-2014-3593 is considered a high-severity vulnerability due to the potential for remote code execution.
2
How do I fix CVE-2014-3593?
To fix CVE-2014-3593, upgrade to a version of luci that is newer than 0.26.0 that addresses this vulnerability.
3
Who is affected by CVE-2014-3593?
CVE-2014-3593 affects remote authenticated users with specific permissions in luci version 0.26.0.
4
What type of vulnerability is CVE-2014-3593?
CVE-2014-3593 is an eval injection vulnerability allowing execution of arbitrary Python code.
5
What are the potential consequences of CVE-2014-3593?
The consequences of CVE-2014-3593 can include unauthorized execution of code, leading to system compromise.