OS Command Injection Vulnerability in gala-gopher on Linux
CVE-2024-24890

7.8HIGH

Key Information:

Vendor

Openeuler

Vendor
CVE Published:
25 March 2024

What is CVE-2024-24890?

The vulnerability in openEuler Gala-Gopher enables OS Command Injection due to improper neutralization of special elements within command execution contexts. This can lead to unauthorized command execution on systems running vulnerable versions of the product. The affected component is located in the program files on Linux systems, specifically within the ioprobe module. Proper mitigation should involve updating to the latest version and applying necessary patches to safeguard against potential exploitation.

Affected Version(s)

gala-gopher Linux 0 <= 1.0.2

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.