CVE-2019-11552
Published Jul 19, 2019
Last updated 3 years ago
Overview
- Description
- Code42 Enterprise and Crashplan for Small Business Client version 6.7 before 6.7.5, 6.8 before 6.8.8, and 6.9 before 6.9.4 allows eval injection. A proxy auto-configuration file, crafted by a lesser privileged user, may be used to execute arbitrary code at a higher privilege as the service user.
- Source
- cve@mitre.org
- NVD status
- Analyzed
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 7
- Impact score
- 5.9
- Exploitability score
- 1
- Vector string
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity
- HIGH
CVSS 2.0
- Type
- Primary
- Base score
- 4.4
- Impact score
- 6.4
- Exploitability score
- 3.4
- Vector string
- AV:L/AC:M/Au:N/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- CWE-94
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:code42:code42_for_enterprise:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "28E60B9E-F766-42C2-979C-A1432B1EEE6D", "versionEndExcluding": "6.7.5", "versionStartIncluding": "6.7" }, { "criteria": "cpe:2.3:a:code42:code42_for_enterprise:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8567BB9A-5F40-45BE-A105-3203190A2C18", "versionEndExcluding": "6.8.8", "versionStartIncluding": "6.8" }, { "criteria": "cpe:2.3:a:code42:code42_for_enterprise:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "85A9B2FE-02C9-4E1A-8AB9-E60EB2DCC482", "versionEndExcluding": "6.9.4", "versionStartIncluding": "6.9" } ], "operator": "OR" } ] }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:code42:crashplan_for_small_business:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "969D004D-A8EA-4C09-913C-0D837C6645B7", "versionEndExcluding": "6.7.5", "versionStartIncluding": "6.7" }, { "criteria": "cpe:2.3:a:code42:crashplan_for_small_business:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "29E9F36F-3722-4C5A-BC81-3473396FE50A", "versionEndExcluding": "6.8.8", "versionStartIncluding": "6.8" }, { "criteria": "cpe:2.3:a:code42:crashplan_for_small_business:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CD2A4C11-7783-4055-AC24-E100F49A0593", "versionEndExcluding": "6.9.4", "versionStartIncluding": "6.9" } ], "operator": "OR" } ] } ]