Command Injection in sequenceserver
Critical severity
GitHub Reviewed
Published
Aug 13, 2024
in
wurmlab/sequenceserver
•
Updated Aug 14, 2024
Description
Published to the GitHub Advisory Database
Aug 13, 2024
Reviewed
Aug 13, 2024
Published by the National Vulnerability Database
Aug 14, 2024
Last updated
Aug 14, 2024
Impact
Several HTTP endpoints did not properly sanitize user input and/or query parameters. This could be exploited to inject and run unwanted shell commands
Patches
Fixed in 3.1.2
Workarounds
No known workarounds
References