Publish GHSA-r3c4-qgcj-4qp2

This commit is contained in:
advisory-database[bot]
2024-12-15 15:32:19 +00:00
parent 2e5c49528a
commit b5c14260b2
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r3c4-qgcj-4qp2",
"modified": "2024-12-15T15:30:53Z",
"published": "2024-12-15T15:30:53Z",
"aliases": [
"CVE-2024-11858"
],
"details": "A flaw was found in Radare2, which contains a command injection vulnerability caused by insufficient input validation when handling Pebble Application files. Maliciously crafted inputs can inject shell commands during command parsing, leading to unintended behavior during file processing",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11858"
},
{
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2329102"
}
],
"database_specific": {
"cwe_ids": [
"CWE-78"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-15T14:15:22Z"
}
}