CVE-2024-28125
Severity CVSS v4.0:
Pending analysis
Type:
CWE-78
OS Command Injections
Publication date:
18/03/2024
Last modified:
10/10/2024
Description
FitNesse all releases allows a remote authenticated attacker to execute arbitrary OS commands. Note: A contributor of FitNesse has claimed that this is not a vulnerability but a product specification and this is currently under further investigation.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL