First published: Tue Jan 17 2023(Updated: )
A vulnerability, which was classified as problematic, was found in galaxy-data-resource up to 14.10.0. This affects an unknown part of the component Command Line Template. The manipulation leads to injection. Upgrading to version 14.10.1 is able to address this issue. The patch is named 50d65f45d3f5be5d1fbff2e45ac5cec075f07d42. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-218451.
Credit: cna@vuldb.com cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Galaxyproject Galaxy | <14.10.1 | |
<14.10.1 |
https://github.com/blankenberg/galaxy-data-resource/commit/50d65f45d3f5be5d1fbff2e45ac5cec075f07d42
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-10062 is a vulnerability found in galaxy-data-resource up to version 14.10.0.
The severity of CVE-2015-10062 is critical with a CVSS score of 9.8.
CVE-2015-10062 allows for injection and affects an unknown part of the component Command Line Template in galaxy-data-resource.
Upgrading to version 14.10.1 of galaxy-data-resource addresses the vulnerability.
You can find more information about CVE-2015-10062 at the following references: [Reference 1](https://github.com/blankenberg/galaxy-data-resource/commit/50d65f45d3f5be5d1fbff2e45ac5cec075f07d42), [Reference 2](https://github.com/blankenberg/galaxy-data-resource/releases/tag/v14.10.1), [Reference 3](https://vuldb.com/?ctiid.218451).