First published: Wed Feb 22 2023(Updated: )
A vulnerability in Imperative framework which allows already-privileged local actors to execute arbitrary shell commands via plugin install/update commands, or maliciously formed environment variables. Impacts Zowe CLI.
Credit: zowe-security@lists.openmainframeproject.org
Affected Software | Affected Version | How to fix |
---|---|---|
Linuxfoundation Zowe | >=1.16.0<1.28.2 | |
Linuxfoundation Zowe | >=2.0.0<2.5.0 |
This issue is fixed in Zowe 1.28.2 or later, and Zowe 2.5.0 or later.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.