CVE-2022-4768
Dropbox merou SSH Public Key public_key.py add_public_key injection
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability was found in Dropbox merou. It has been classified as critical. Affected is the function add_public_key of the file grouper/public_key.py of the component SSH Public Key Handler. The manipulation of the argument public_key_str leads to injection. It is possible to launch the attack remotely. The name of the patch is d93087973afa26bc0a2d0a5eb5c0fde748bdd107. It is recommended to apply a patch to fix this issue. VDB-216906 is the identifier assigned to this vulnerability.
Se encontró una vulnerabilidad en Dropbox merou. Ha sido clasificada como crítica. La función add_public_key del archivo grouper/public_key.py del componente SSH Public Key Handler es afectada por la vulnerabilidad. La manipulación del argumento public_key_str conduce a la inyección. Es posible lanzar el ataque de forma remota. El nombre del parche es d93087973afa26bc0a2d0a5eb5c0fde748bdd107. Se recomienda aplicar un parche para solucionar este problema. VDB-216906 es el identificador asignado a esta vulnerabilidad.
Es wurde eine kritische Schwachstelle in Dropbox merou ausgemacht. Hiervon betroffen ist die Funktion add_public_key der Datei grouper/public_key.py der Komponente SSH Public Key Handler. Durch Manipulieren des Arguments public_key_str mit unbekannten Daten kann eine injection-Schwachstelle ausgenutzt werden. Der Angriff kann über das Netzwerk angegangen werden. Der Patch wird als d93087973afa26bc0a2d0a5eb5c0fde748bdd107 bezeichnet. Als bestmögliche Massnahme wird Patching empfohlen.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-12-27 CVE Reserved
- 2022-12-27 CVE Published
- 2024-08-03 CVE Updated
- 2025-01-22 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://vuldb.com/?id.216906 | Technical Description |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/dropbox/merou/commit/d93087973afa26bc0a2d0a5eb5c0fde748bdd107 | 2024-05-17 | |
https://github.com/dropbox/merou/pull/673 | 2024-05-17 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Dropbox Search vendor "Dropbox" | Merou Search vendor "Dropbox" for product "Merou" | < 2022-03-28 Search vendor "Dropbox" for product "Merou" and version " < 2022-03-28" | - |
Affected
|