Description
A command injection vulnerability in Cribl Edge for Linux versions 3.2.0 through 4.17.0 allows a local unprivileged user to execute arbitrary commands in the context of the Cribl Edge service account.
Problem types
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Product status
3.2.0 (semver) before 4.17.1
4.17.1 (semver)
Credits
Zach Rayburn, Cribl Product Security
References
docs.cribl.io/edge/release-notes/release-v4171 (Cribl Edge 4.17.1 Security Fixes)
trust.cribl.io/notifications (Cribl Trust Portal)