CVE-2024-24892: Unauthorized RCE in migration-tools
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), Improper Privilege Management vulnerability in openEuler migration-tools on Linux allows Command Injection, Restful Privilege Elevation. This vulnerability is associated with program files https://gitee.Com/openeuler/migration-tools/blob/master/index.Py.
This issue affects migration-tools: from 1.0.0 through 1.0.1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-24892?
CVE-2024-24892 is classified as a high-severity vulnerability due to its potential for OS command injection and privilege escalation.
How do I fix CVE-2024-24892?
To fix CVE-2024-24892, you should update the openEuler migration-tools to the latest version beyond 1.0.1.
What systems are affected by CVE-2024-24892?
CVE-2024-24892 affects openEuler migration-tools version 1.0.0 up to and including version 1.0.1.
What kind of vulnerability is CVE-2024-24892?
CVE-2024-24892 is an OS command injection vulnerability that allows improper privilege management.
Can CVE-2024-24892 allow unauthorized access?
Yes, CVE-2024-24892 can allow for unauthorized access through command injection and privilege escalation.