CVE Vulnerabilities

CVE-2022-44544

Published: Nov 06, 2022 | Modified: Nov 21, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Mahara 21.04 before 21.04.7, 21.10 before 21.10.5, 22.04 before 22.04.3, and 22.10 before 22.10.0 potentially allow a PDF export to trigger a remote shell if the site is running on Ubuntu and the flag -dSAFER is not set with Ghostscript.

Affected Software

Name Vendor Start Version End Version
Mahara Mahara 21.04.0 (including) 21.04.7 (excluding)
Mahara Mahara 21.10.0 (including) 21.10.5 (excluding)
Mahara Mahara 22.04.0 (including) 22.04.3 (excluding)
Mahara Mahara 22.10.0-rc1 (including) 22.10.0-rc1 (including)

References