Rebar3 versions 3.0.0-beta.3 to 3.13.2 are vulnerable to OS command injection via URL parameter of dependency specification.
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
Link | Tags |
---|---|
http://packetstormsecurity.com/files/159027/Rebar3-3.13.2-Command-Injection.html | exploit vdb entry third party advisory |
https://vuln.be/post/rebar3-command-injection/ | third party advisory |
https://github.com/vulnbe/poc-rebar3.git | third party advisory |