CVE-2022-24753
Published on: Not Yet Published
Last Modified on: 03/12/2022 02:51:00 AM UTC
Certain versions of Windows from Microsoft contain the following vulnerability:
Stripe CLI is a command-line tool for the Stripe eCommerce platform. A vulnerability in Stripe CLI exists on Windows when certain commands are run in a directory where an attacker has planted files. The commands are `stripe login`, `stripe config -e`, `stripe community`, and `stripe open`. MacOS and Linux are unaffected. An attacker who successfully exploits the vulnerability can run arbitrary code in the context of the current user. The update addresses the vulnerability by throwing an error in these situations before the code can run.Users are advised to upgrade to version 1.7.13. There are no known workarounds for this issue.
- CVE-2022-24753 has been assigned by
[email protected] to track the vulnerability - currently rated as HIGH severity.
- Affected Vendor/Software:
stripe - stripe-cli version < 1.7.13
CVSS3 Score: 7 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
LOCAL | HIGH | LOW | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVSS2 Score: 4.4 - MEDIUM
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
LOCAL | MEDIUM | NONE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
PARTIAL | PARTIAL | PARTIAL |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Vulnerability in Stripe CLI < 1.7.13 · Advisory · stripe/stripe-cli · GitHub | github.com text/html |
![]() |
replace exec package (#820) · stripe/[email protected] · GitHub | github.com text/html |
![]() |
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Operating System | Microsoft | Windows | - | All | All | All |
Application | Stripe | Stripe Cli | All | All | All | All |
- cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*:
- cpe:2.3:a:stripe:stripe_cli:*:*:*:*:*:*:*:*:
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2022-24753 : Stripe CLI is a command-line tool for the Stripe eCommerce platform. A vulnerability in Stripe CLI… twitter.com/i/web/status/1… | 2022-03-09 22:38:04 |
![]() |
CVE-2022-24753 | 2022-03-09 23:38:22 |