pizzashack rssh 2.3.4

CPE Details

pizzashack rssh 2.3.4
2.3.4
2013-01-11
13h47 +00:00
2013-01-16
18h26 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:pizzashack:rssh:2.3.4:*:*:*:*:*:*:*

Informations

Vendor

pizzashack

Product

rssh

Version

2.3.4

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2019-3463 2019-02-06 19h00 +00:00 Insufficient sanitization of arguments passed to rsync can bypass the restrictions imposed by rssh, a restricted shell that should restrict users to perform only rsync operations, resulting in the execution of arbitrary shell commands.
9.8
Critical
CVE-2019-3464 2019-02-06 19h00 +00:00 Insufficient sanitization of environment variables passed to rsync can bypass the restrictions imposed by rssh, a restricted shell that should restrict users to perform only rsync operations, resulting in the execution of arbitrary shell commands.
9.8
Critical
CVE-2019-1000018 2019-02-04 21h00 +00:00 rssh version 2.3.4 contains a CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in allowscp permission that can result in Local command execution. This attack appear to be exploitable via An authorized SSH user with the allowscp permission.
7.8
High