CVE Vulnerabilities

CVE-2022-39051

Improper Control of Dynamically-Managed Code Resources

Published: Sep 05, 2022 | Modified: Nov 21, 2024
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Attacker might be able to execute malicious Perl code in the Template toolkit, by having the admin installing an unverified 3th party package

Weakness

The product does not properly restrict reading from or writing to dynamically-managed code resources such as variables, objects, classes, attributes, functions, or executable instructions or statements.

Affected Software

NameVendorStart VersionEnd Version
OtrsOtrs6.0.0 (including)6.0.32 (including)
OtrsOtrs7.0.0 (including)7.0.37 (excluding)
OtrsOtrs8.0.0 (including)8.0.25 (excluding)
ZnunyUbuntukinetic*
ZnunyUbuntulunar*
ZnunyUbuntumantic*
ZnunyUbuntuoracular*
ZnunyUbuntuplucky*
ZnunyUbuntutrusty*
ZnunyUbuntuxenial*

Potential Mitigations

References