CVE-2022-24803
Summary
| CVE | CVE-2022-24803 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-04-01 00:15:00 UTC |
| Updated | 2022-04-11 20:15:00 UTC |
| Description | Asciidoctor-include-ext is Asciidoctor’s standard include processor reimplemented as an extension. Versions prior to 0.4.0, when used to render user-supplied input in AsciiDoc markup, may allow an attacker to execute arbitrary system commands on the host operating system. This attack is possible even when `allow-uri-read` is disabled! The problem has been patched in the referenced commits. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Command Injection vulnerability in asciidoctor-include-ext · Advisory · jirutka/asciidoctor-include-ext · GitHub |
CONFIRM |
github.com |
|
| Make #read_lines code more robust, avoid using IO.open directly · jirutka/asciidoctor-include-ext@cbaccf3 · GitHub |
MISC |
github.com |
|
| Fix command injection vulnerability · jirutka/asciidoctor-include-ext@c7ea001 · GitHub |
MISC |
github.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 182675 Debian Security Update for ruby-asciidoctor-include-ext (CVE-2022-24803)