Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in OpenNebula OpenNebula core on Linux allows Remote Code Inclusion.

Project Subscriptions

Vendors Products
Linux Kernel Subscribe
Opennebula Subscribe
Opennebula Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2022-40055 Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in OpenNebula OpenNebula core on Linux allows Remote Code Inclusion.
Fixes

Solution

Upgrade to OpenNebula 6.4.2 EE LTS and configure the CONTEXT_RESTRICTED_DIRS and CONTEXT_SAFE_DIRS properties in oned.conf


Workaround

Do not allow regular users to use the FILES directive inside their VM templates, instead set up a context files datastore, and allow users to upload and reference their files from that datastore, using the FILES_DS directive.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: blackberry

Published:

Updated: 2024-08-03T10:29:21.021Z

Reserved: 2022-08-05T00:00:00

Link: CVE-2022-37425

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-10-28T16:15:16.080

Modified: 2024-11-21T07:14:58.160

Link: CVE-2022-37425

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses