CVE-2021-38173: Command Injection
Published Aug 7, 2021
·Updated
Btrbk before 0.31.2 allows command execution because of the mishandling of remote hosts filtering SSH commands using sshfilterbtrbk.sh in authorizedkeys.
Affected Software
4 affected components
Digint Btrbk<0.31.2
Debian Debian Linux=9.0
Fedoraproject Fedora=34
Fedoraproject Fedora=35
Remediation
Event History
Aug 7, 2021
CVE Published
via MITRE·06:58 PM
Data Sourced
via MITRE·06:58 PM
Description
Data Sourced
via NVD·07:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-38173?
CVE-2021-38173 has a high severity rating due to its potential for remote command execution.
2
How do I fix CVE-2021-38173?
To fix CVE-2021-38173, upgrade Btrbk to version 0.31.2 or later.
3
Which systems are affected by CVE-2021-38173?
CVE-2021-38173 affects Btrbk versions prior to 0.31.2, as well as Debian 9.0 and Fedora 34 and 35.
4
What type of vulnerability is CVE-2021-38173?
CVE-2021-38173 is classified as a command execution vulnerability.
5
Is CVE-2021-38173 being actively exploited?
There have been reports indicating that CVE-2021-38173 could be actively exploited in the wild.