CVE-2024-42360
Severity CVSS v4.0:
Pending analysis
Type:
CWE-77
Command Injection
Publication date:
14/08/2024
Last modified:
16/08/2024
Description
SequenceServer lets you rapidly set up a BLAST+ server with an intuitive user interface for personal or group use. Several HTTP endpoints did not properly sanitize user input and/or query parameters. This could be exploited to inject and run unwanted shell commands. This vulnerability has been fixed in 3.1.2.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:wurmlab:sequenceserver:*:*:*:*:*:ruby:*:* | 3.1.2 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



