CVE-2022-37425: The FILES directive inside a VM template allows execution of uploaded files when the template is instantiated, resulting in a Remote Code Execution (RCE) attack.
Published Oct 28, 2022
·Updated
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in OpenNebula OpenNebula core on Linux allows Remote Code Inclusion.
Affected Software
4 affected components
OpenNebula OpenNebula<6.4.2
Linux Linux kernel
All of the following
OpenNebula OpenNebula<6.4.2
Linux Linux kernel
Remediation
Information
Upgrade to OpenNebula 6.4.2 EE LTS and configure the CONTEXT_RESTRICTED_DIRS and CONTEXT_SAFE_DIRS properties in oned.conf
Event History
Oct 28, 2022
CVE Published
03:09 PM
Data Sourced
03:09 PM
RemedyDescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2022-37425?
CVE-2022-37425 is classified as a high severity vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2022-37425?
To fix CVE-2022-37425, upgrade OpenNebula to version 6.4.2 or later.
3
What type of vulnerability is CVE-2022-37425?
CVE-2022-37425 is an improper neutralization of special elements used in a command, also known as command injection.
4
Which systems are affected by CVE-2022-37425?
CVE-2022-37425 affects OpenNebula core on Linux systems up to version 6.4.2.
5
Can CVE-2022-37425 lead to remote code inclusion?
Yes, CVE-2022-37425 allows for remote code inclusion due to its command injection nature.