acme.sh before 3.0.6 runs arbitrary commands from a remote server via eval, as exploited in the wild in June 2023.
References
Configurations
History
No history.
Information
Published : 2023-07-13 03:15
Updated : 2024-11-21 08:13
NVD link : CVE-2023-38198
Mitre link : CVE-2023-38198
CVE.ORG link : CVE-2023-38198
JSON object : View
Products Affected
acme.sh_project
- acme.sh
CWE