CVE-2019-11076

Cribl UI 1.5.0 allows remote attackers to run arbitrary commands via an unauthenticated web request.
References
Link Resource
https://github.com/livehybrid/poc-cribl-rce Exploit Third Party Advisory
https://docs.cribl.io/blog/release-v151 Release Notes Vendor Advisory
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:cribl:cribl:1.5.0:*:*:*:*:*:*:*

Information

Published : 2019-04-23 11:29

Updated : 2019-04-29 11:43


NVD link : CVE-2019-11076

Mitre link : CVE-2019-11076


JSON object : View

CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

Advertisement

dedicated server usa

Products Affected

cribl

  • cribl