CVE-2018-14772: OS Command Injection
Published Oct 16, 2018
·Updated
Pydio 4.2.1 through 8.2.1 has an authenticated remote code execution vulnerability in which an attacker with administrator access to the web application can execute arbitrary code on the underlying system via Command Injection.
Affected Software
1 affected component
Pydio Pydio>=4.2.1<=8.2.1
Remediation
Patch Available
Event History
Oct 16, 2018
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-14772?
The severity of CVE-2018-14772 is critical with a severity value of 7.2.
2
How does CVE-2018-14772 affect Pydio?
CVE-2018-14772 affects Pydio versions 4.2.1 through 8.2.1.
3
What is the vulnerability in CVE-2018-14772?
CVE-2018-14772 is an authenticated remote code execution vulnerability in Pydio.
4
How can an attacker exploit CVE-2018-14772?
An attacker with administrator access to the Pydio web application can execute arbitrary code on the underlying system via Command Injection.
5
Is there a fix for CVE-2018-14772?
Yes, make sure to update Pydio to a version that is not vulnerable (above 8.2.1).