CVE-2022-24552
06.02.2022, 21:15
A flaw was found in the REST API in StarWind Stack. REST command, which manipulates a virtual disk, doesnt check input parameters. Some of them go directly to bash as part of a script. An attacker with non-root user access can inject arbitrary data into the command that will be executed with root privileges. This affects StarWind SAN and NAS v0.2 build 1633.
Vendor | Product | Version |
---|---|---|
starwindsoftware | nas | 𝑥 < 0.2 |
starwindsoftware | san | 𝑥 < 0.2 |
𝑥
= Vulnerable software versions