OS Command Injection Vulnerability in Rebar3 by Erlang Solutions
CVE-2020-13802

9.8CRITICAL

Key Information:

Vendor

Erlang

Status
Vendor
CVE Published:
2 September 2020

What is CVE-2020-13802?

Rebar3, a build tool for Erlang applications, is susceptible to OS command injection through URL parameters related to dependency specifications. This vulnerability can allow attackers to execute arbitrary commands on the host system, potentially leading to unauthorized access or data manipulation. Users of Rebar3 versions ranging from 3.0.0-beta.3 to 3.13.2 should update to the latest version to mitigate this risk.

References

EPSS Score

44% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.