CVE-2024-49400
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
17/10/2024
Last modified:
01/11/2024
Description
Tacquito prior to commit 07b49d1358e6ec0b5aa482fcd284f509191119e2 was not properly performing regex matches on authorized commands and arguments. Configured allowed commands/arguments were intended to require a match on the entire string, but instead only enforced a match on a sub-string. That would have potentially allowed unauthorized commands to be executed.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL



