CVE-2024-28114
Severity CVSS v4.0:
Pending analysis
Type:
CWE-74
Injection
Publication date:
12/03/2024
Last modified:
20/02/2025
Description
Peering Manager is a BGP session management tool. There is a Server Side Template Injection vulnerability that leads to Remote Code Execution in Peering Manager
Impact
Base Score 3.x
8.10
Severity 3.x
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:peering-manager:peering_manager:*:*:*:*:*:*:*:* | 1.8.3 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://github.com/peering-manager/peering-manager/commit/8a865fb596c11ad7caf45aef317d8fcbce7f85ff
- https://github.com/peering-manager/peering-manager/security/advisories/GHSA-q37x-qfrx-jcv6
- https://owasp.org/www-community/attacks/Command_Injection
- https://owasp.org/www-project-web-security-testing-guide/v41/4-Web_Application_Security_Testing/07-Input_Validation_Testing/18-Testing_for_Server_Side_Template_Injection
- https://stackoverflow.com/questions/73939573/how-to-sanitise-string-of-python-code-with-python
- https://github.com/peering-manager/peering-manager/commit/8a865fb596c11ad7caf45aef317d8fcbce7f85ff
- https://github.com/peering-manager/peering-manager/security/advisories/GHSA-q37x-qfrx-jcv6
- https://owasp.org/www-community/attacks/Command_Injection
- https://owasp.org/www-project-web-security-testing-guide/v41/4-Web_Application_Security_Testing/07-Input_Validation_Testing/18-Testing_for_Server_Side_Template_Injection
- https://stackoverflow.com/questions/73939573/how-to-sanitise-string-of-python-code-with-python