← Back to CVE List

CVE-2022-44794

Published: 2022-11-07T04:15Z
Last Modified: 2024-11-21T07:28Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
An issue was discovered in Object First Ootbi BETA build 1.0.7.712. Management protocol has a flow which allows a remote attacker to execute arbitrary Bash code with root privileges. The command that sets the hostname doesn't validate input parameters. As a result, arbitrary data goes directly to the Bash interpreter. An attacker would need credentials to exploit this vulnerability. This is fixed in Object First Ootbi BETA build 1.0.13.1611. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt