CVE-2024-54794: Command Injection
Published Jan 21, 2025
·Updated
The script input feature of SpagoBI 3.5.1 allows arbitrary code execution.
Affected Software
2 affected components
SpagoBI SpagoBI
eng SpagoBI=3.5.1
Event History
Jan 21, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-54794?
CVE-2024-54794 is categorized as a high severity vulnerability due to its potential for arbitrary code execution.
2
How do I fix CVE-2024-54794?
To fix CVE-2024-54794, upgrade to a patched version of SpagoBI that addresses the arbitrary code execution issue.
3
What is the impact of exploiting CVE-2024-54794?
Exploitation of CVE-2024-54794 can lead to the execution of arbitrary code on the affected system, compromising its integrity.
4
Which versions of SpagoBI are affected by CVE-2024-54794?
CVE-2024-54794 specifically affects SpagoBI 3.5.1 and possibly earlier versions.
5
How can I determine if my system is vulnerable to CVE-2024-54794?
You can determine if your system is vulnerable to CVE-2024-54794 by checking if it is running SpagoBI version 3.5.1 or lower.