F5-K06345931: Command Injection
Published Feb 1, 2023
·Updated
Processing F5OS tenant file names may allow for command injection.
Affected Software
2 affected componentsFixes available
F5 F5OS=1.2.0
1.3.03
F5 F5OS>=1.3.0<=1.3.2
1.5.0
Event History
Feb 1, 2023
Advisory Published
via F5·01:30 PM
Frequently Asked Questions
1
What is the severity of F5-K06345931?
The severity of F5-K06345931 is classified as critical due to its potential for command injection.
2
How do I fix F5-K06345931?
To fix F5-K06345931, upgrade to F5OS-A version 1.3.03 or F5OS-C version 1.5.0 or higher.
3
What are the affected versions for F5-K06345931?
Affected versions for F5-K06345931 include F5OS-A version 1.2.0 and F5OS-C versions from 1.3.0 to 1.3.2.
4
What type of vulnerability is F5-K06345931?
F5-K06345931 is a command injection vulnerability that arises from processing tenant file names.
5
Is there a workaround for F5-K06345931?
Currently, there are no official workarounds for F5-K06345931, and patching is recommended.