Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: GSA_kwCzR0hTQS04cDQyLTc1OTctcDJmNs4AA7Wb
dcnnt-py is vulnerable to command injection via Notification Handler
A vulnerability was found in cyanomiko dcnnt-py up to 0.9.0. It has been classified as critical. Affected is the function main of the file dcnnt/plugins/notifications.py of the component Notification Handler. The manipulation leads to command injection. It is possible to launch the attack remotely. Upgrading to version 0.9.1 is able to address this issue. The patch is identified as b4021d784a97e25151a5353aa763a741e9a148f5. It is recommended to upgrade the affected component. VDB-262230 is the identifier assigned to this vulnerability.
Permalink: https://github.com/advisories/GHSA-8p42-7597-p2f6JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS04cDQyLTc1OTctcDJmNs4AA7Wb
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: 7 months ago
Updated: 7 months ago
CVSS Score: 6.3
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Identifiers: GHSA-8p42-7597-p2f6, CVE-2023-1000
References:
- https://nvd.nist.gov/vuln/detail/CVE-2023-1000
- https://github.com/cyanomiko/dcnnt-py/pull/23
- https://github.com/cyanomiko/dcnnt-py/commit/b4021d784a97e25151a5353aa763a741e9a148f5
- https://github.com/cyanomiko/dcnnt-py/releases/tag/0.9.1
- https://vuldb.com/?ctiid.262230
- https://vuldb.com/?id.262230
- https://github.com/advisories/GHSA-8p42-7597-p2f6
Blast Radius: 0.0
Affected Packages
pypi:dcnnt
Dependent packages: 0Dependent repositories: 1
Downloads: 1,386 last month
Affected Version Ranges: <= 0.9.0
Fixed in: 0.9.1
All affected versions: 0.3.3, 0.3.4, 0.3.5, 0.3.6, 0.3.7, 0.3.8, 0.4.0, 0.5.0, 0.6.0, 0.7.0, 0.7.1, 0.8.0, 0.9.0
All unaffected versions: 0.9.1, 0.9.2, 0.10.0