Home
HIGH: 7.4 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:LDefault status
unaffected
Any version before 0.6.11
affected
Description
OpenOps before 0.6.11 allows remote code execution in the Terraform block.
Problem types
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Product status
Any version before 0.6.11
References
github.com/openops-cloud/openops/pull/1767
linear.app/openops/issue/OPS-3254
github.com/openops-cloud/openops/releases/tag/0.6.11
github.com/openops-cloud/openops/compare/0.6.10...0.6.11
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.