CVE-2014-2888 – sfpagent
Package
Manager: gem
Name: sfpagent
Vulnerable Version: >=0 <0.4.15
Severity
Level: High
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N/E:H/RL:U/RC:C
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
EPSS: 0.00734 pctl0.71899
Details
sfpagent Command Injection vulnerability `lib/sfpagent/bsig.rb` in the sfpagent gem before 0.4.15 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in the module name in a JSON request.
Metadata
Created: 2017-10-24T18:33:36Z
Modified: 2025-04-13T23:28:09Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2017/10/GHSA-vm28-mrm7-fpjq/GHSA-vm28-mrm7-fpjq.json
CWE IDs: ["CWE-77"]
Alternative ID: GHSA-vm28-mrm7-fpjq
Finding: F422
Auto approve: 1