Vulnerability Details CVE-2019-9924
rbash in Bash before 4.4-beta2 did not prevent the shell user from modifying BASH_CMDS, thus allowing the user to execute any command with the permissions of the shell.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 50.2%
CVSS Severity
CVSS v3 Score 7.8
CVSS v2 Score 7.2
Products affected by CVE-2019-9924
-
-
cpe:2.3:a:gnu:bash:1.14.0
-
cpe:2.3:a:gnu:bash:1.14.1
-
cpe:2.3:a:gnu:bash:1.14.2
-
cpe:2.3:a:gnu:bash:1.14.3
-
cpe:2.3:a:gnu:bash:1.14.4
-
cpe:2.3:a:gnu:bash:1.14.5
-
cpe:2.3:a:gnu:bash:1.14.6
-
cpe:2.3:a:gnu:bash:1.14.7
-
-
-
cpe:2.3:a:gnu:bash:2.01.1
-
-
cpe:2.3:a:gnu:bash:2.02.1
-
-
-
-
-
cpe:2.3:a:gnu:bash:3.0.16
-
-
-
cpe:2.3:a:gnu:bash:3.2.48
-
cpe:2.3:a:gnu:bash:3.2.57
-
-
-
-
cpe:2.3:a:gnu:bash:4.2.53
-
-
cpe:2.3:a:gnu:bash:4.3.30
-
-
cpe:2.3:a:netapp:hci_management_node:-
-
cpe:2.3:a:netapp:solidfire:-
-
cpe:2.3:o:canonical:ubuntu_linux:12.04
-
cpe:2.3:o:canonical:ubuntu_linux:14.04
-
cpe:2.3:o:canonical:ubuntu_linux:16.04
-
cpe:2.3:o:debian:debian_linux:8.0
-
cpe:2.3:o:opensuse:leap:42.3