Command Injection Vulnerability in NSA Ghidra's Launch Script
CVE-2023-22671
9.8CRITICAL
What is CVE-2023-22671?
In NSA Ghidra, a command injection vulnerability exists due to user-provided input being passed to eval in the launch.sh script when executing analyzeHeadless. This flaw can be exploited with untrusted input, allowing attackers to execute arbitrary commands on the system. Users of Ghidra versions prior to 10.2.2 are advised to review their input sanitization procedures and upgrade to mitigate potential threats.
