CVE-2020-24364: High severity ethz minetime vulnerability
Published Aug 24, 2020
·Updated
MineTime through 1.8.5 allows arbitrary command execution via the notes field in a meeting. Could lead to RCE via meeting invite.
Affected Software
1 affected component
Ethz Minetime<=1.8.5
Event History
Aug 24, 2020
CVE Published
via MITRE·06:35 PM
Data Sourced
via MITRE·06:35 PM
Description
Frequently Asked Questions
1
What is CVE-2020-24364?
CVE-2020-24364 is a vulnerability that allows arbitrary command execution in MineTime through version 1.8.5 via the notes field in a meeting.
2
How severe is CVE-2020-24364?
CVE-2020-24364 has a severity score of 8.8 (high).
3
How does CVE-2020-24364 work?
CVE-2020-24364 allows an attacker to execute arbitrary commands by exploiting the notes field in a meeting in MineTime.
4
How can CVE-2020-24364 be exploited?
CVE-2020-24364 can be exploited by injecting malicious commands into the notes field of a meeting and then convincing a user to view or interact with the meeting invite.
5
How do I mitigate CVE-2020-24364?
To mitigate CVE-2020-24364, it is recommended to update to a version of MineTime that is not affected by the vulnerability.