Description
Command injection in alerts in CoolerControl/coolercontrold <4.0.0 allows authenticated attackers to execute arbitrary code as root via injected bash commands in alert names
Problem types
CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Product status
3.1.0 (semver) before 4.0.0
Credits
https://gitlab.com/lassi-3
References
gitlab.com/...1.0/coolercontrold/src/alerts.rs?ref_type=tags
gitlab.com/coolercontrol/coolercontrol/-/releases/4.0.0