First published: Fri Oct 28 2022(Updated: )
Unrestricted Upload of File with Dangerous Type vulnerability in OpenNebula OpenNebula core on Linux allows File Content Injection.
Credit: secure@blackberry.com
Affected Software | Affected Version | How to fix |
---|---|---|
npm | <6.4.2 | |
Linux Kernel | ||
All of | ||
npm | <6.4.2 | |
Linux Kernel |
Upgrade to OpenNebula 6.4.2 EE LTS
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-37426 is considered a critical vulnerability due to the potential for file content injection.
To fix CVE-2022-37426, update OpenNebula to version 6.4.2 or a later release that addresses this vulnerability.
CVE-2022-37426 affects OpenNebula versions prior to 6.4.2 running on Linux.
CVE-2022-37426 facilitates file content injection attacks, which can lead to unauthorized code execution.
CVE-2022-37426 is specific to OpenNebula and does not have direct relations to other listed vulnerabilities.