CVE-2022-24552: OS Command Injection
A flaw was found in the REST API in StarWind Stack. REST command, which manipulates a virtual disk, doesn’t check input parameters. Some of them go directly to bash as part of a script. An attacker with non-root user access can inject arbitrary data into the command that will be executed with root privileges. This affects StarWind SAN and NAS v0.2 build 1633.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this flaw?
The vulnerability ID for this flaw is CVE-2022-24552.
What is the severity level of CVE-2022-24552?
The severity level of CVE-2022-24552 is critical.
What is the affected software?
The affected software is StarWind Stack version up to and excluding 0.2, including Starwindsoftware Nas and Starwindsoftware San.
What is the CWE ID for this vulnerability?
The CWE ID for this vulnerability is CWE-78.
How can an attacker exploit this vulnerability?
An attacker with non-root user access can inject arbitrary data into a REST command that manipulates a virtual disk, which will be executed with root privileges.