CVE-2022-34558 – global-workqueue
Package
Manager: pip
Name: global-workqueue
Vulnerable Version: =1.4.1rc5 || >=1.4.1rc5 <2.0.4
Severity
Level: Critical
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS: 0.0076 pctl0.72417
Details
WMAgent arbitrary code execution via a crafted dbs-client package WMAgent v1.3.3rc2 and 1.3.3rc1, reqmgr2 1.4.1rc5 and 1.4.0rc2, reqmon 1.4.1rc5, and global-workqueue 1.4.1rc5 allows attackers to execute arbitrary code via a crafted dbs-client package.
Metadata
Created: 2022-07-29T00:00:17Z
Modified: 2024-11-26T18:46:36Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/07/GHSA-4vq7-8699-4xgc/GHSA-4vq7-8699-4xgc.json
CWE IDs: []
Alternative ID: GHSA-4vq7-8699-4xgc
Finding: F422
Auto approve: 1