CVE-2020-7698: Command Injection
Published Jul 29, 2020
·Updated
This affects the package Gerapy from 0 and before 0.9.3. The input being passed to Popen, via the projectconfigure endpoint, isn’t being sanitized.
Affected Software
2 affected componentsFixes available
pip/gerapy<0.9.3
0.9.3
Gerapy Gerapy>=0.0.0<0.9.3
Remediation
Patch Available
Event History
Jul 29, 2020
CVE Published
via MITRE·12:40 PM
Data Sourced
via MITRE·12:40 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
May 6, 2021
Advisory Published
06:52 PM
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
CVE-2020-7698
2
What is the severity of CVE-2020-7698?
The severity of CVE-2020-7698 is critical with a severity value of 9.8.
3
Which package and versions are affected by CVE-2020-7698?
The package Gerapy versions 0 up to, but not including, 0.9.3 are affected by CVE-2020-7698.
4
What is the root cause of CVE-2020-7698 vulnerability?
The input being passed to Popen, via the project_configure endpoint, in Gerapy is not being properly sanitized.
5
Is there a fix available for CVE-2020-7698?
Yes, updating Gerapy to version 0.9.3 or later will fix CVE-2020-7698.