CVE-2023-45158: Command Injection
Published Oct 16, 2023
·Updated
An OS command injection vulnerability exists in web2py 2.24.1 and earlier. When the product is configured to use notifySendHandler for logging (not the default configuration), a crafted web request may execute an arbitrary OS command on the web server using the product.
Affected Software
1 affected component
Web2py Web2py<=2.24.1
Remediation
Event History
Oct 16, 2023
CVE Published
via MITRE·07:53 AM
Data Sourced
via MITRE·07:53 AM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2023-45158?
CVE-2023-45158 is an OS command injection vulnerability in web2py 2.24.1 and earlier, allowing execution of arbitrary OS commands on the web server.
2
How severe is CVE-2023-45158?
CVE-2023-45158 has a severity level of 9.8 (Critical).
3
How can I fix CVE-2023-45158?
To fix CVE-2023-45158, update your web2py installation to version 2.24.2 or later.
4
What is web2py?
web2py is a free, open-source web application framework written in Python.
5
Where can I download web2py?
You can download web2py from the official website at http://web2py.com/init/default/download.