CVE-2011-2649

Severity
7.5HIGH
EPSS
0.4%
top 40.89%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 23
Latest updateMay 17

Description

Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows attackers to execute arbitrary commands via shell metacharacters in an unspecified FileUtils function call.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-mw98-cjvm-vp82: Kiwi before 32022-05-17
CVEList
CVE-2011-2649: Kiwi before 32011-08-23
CVE-2011-2649 (HIGH CVSS 7.5) | Kiwi before 3.74.2 | cvebase.io