CVE-2019-1000018

Source
https://cve.org/CVERecord?id=CVE-2019-1000018
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-1000018.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2019-1000018
Downstream
Published
2019-02-04T21:29:01.377Z
Modified
2026-02-13T00:21:41.751924Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

rssh version 2.3.4 contains a CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in allowscp permission that can result in Local command execution. This attack appear to be exploitable via An authorized SSH user with the allowscp permission.

References

Affected packages

Git / github.com/numpy/numpy

Affected ranges

Type
GIT
Repo
https://github.com/numpy/numpy
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected

Affected versions

Other
pre-removal-numpybook
with_maskna
v0.*
v0.2.2
v0.3.0
v1.*
v1.21.0.dev0
v1.22.0.dev0
v1.23.0.dev0
v1.24.0.dev0
v1.25.0.dev0
v2.*
v2.0.0.dev0
v2.1.0.dev0
v2.2.0.dev0
v2.3.0
v2.3.0.dev0
v2.3.0rc1
v2.3.1
v2.3.2
v2.3.3
v2.3.4

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-1000018.json"