{ "schema_version": "1.4.0", "id": "GHSA-p882-2j97-m4hp", "modified": "2024-04-04T06:06:23Z", "published": "2023-07-13T03:30:48Z", "aliases": [ "CVE-2023-38198" ], "details": "acme.sh before 3.0.6 runs arbitrary commands from a remote server via eval, as exploited in the wild in June 2023.", "severity": [ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38198" }, { "type": "WEB", "url": "https://github.com/acmesh-official/acme.sh/issues/4659" }, { "type": "WEB", "url": "https://github.com/acmesh-official/acme.sh/releases/tag/3.0.6" }, { "type": "WEB", "url": "https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/heXVr8o83Ys" }, { "type": "WEB", "url": "https://news.ycombinator.com/item?id=36252310" }, { "type": "WEB", "url": "https://news.ycombinator.com/item?id=36254093" }, { "type": "WEB", "url": "https://www.reddit.com/r/netsec/comments/144ygg7/acmesh_runs_arbitrary_commands_from_a_remote" }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2023/07/13/1" } ], "database_specific": { "cwe_ids": [ "CWE-94" ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-07-13T03:15:09Z" } }