Arbitrary Code Injection Affecting cbpi4 package, versions [,4.4.1)
Threat Intelligence
EPSS
0.05% (17th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-PYTHON-CBPI4-6808834
- published 5 May 2024
- disclosed 2 May 2024
- credit Pondzik
How to fix?
Upgrade cbpi4
to version 4.4.1 or higher.
Overview
cbpi4 is a CraftBeerPi4 Brewing Software
Affected versions of this package are vulnerable to Arbitrary Code Injection via the logtime
parameter to a GET request, which is passed directly to os.system()
and executed.
References
CVSS Scores
version 3.1