CVE-2018-5702: High severity transmissionbt Transmission vulnerability
Transmission through 2.92 relies on X-Transmission-Session-Id (which is not a forbidden header for Fetch) for access control, which allows remote attackers to execute arbitrary RPC commands, and consequently write to arbitrary files, via POST requests to /transmission/rpc in conjunction with a DNS rebinding attack.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/transmissionto a version that resolves this vulnerability.Fixed in 2.94-2+deb10u2Fixed in 3.00-1Fixed in 3.00-2.1+deb12u1Fixed in 4.0.2-1
Event History
Frequently Asked Questions
What is CVE-2018-5702?
CVE-2018-5702 is a vulnerability in Transmission through version 2.92 that allows remote attackers to execute arbitrary RPC commands and write to arbitrary files.
What is the severity of CVE-2018-5702?
CVE-2018-5702 has a severity rating of 8.8 (high).
How does CVE-2018-5702 affect Transmission?
CVE-2018-5702 affects Transmission versions up to 2.92.
How can I fix CVE-2018-5702 in Transmission?
To fix CVE-2018-5702 in Transmission, update to version 2.94-2+deb10u2, 3.00-1, 3.00-2.1+deb12u1, or 4.0.2-1.
Where can I find more information about CVE-2018-5702?
You can find more information about CVE-2018-5702 at the following references: [link1], [link2], [link3].