Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2021-45444

In zsh before 5.8.1, an attacker can achieve code execution if they control a command output inside the prompt, as demonstrated by a %F argument. This occurs because of recursive PROMPT_SUBST expansion.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 25.3%
CVSS Severity
CVSS v3 Score 7.8
CVSS v2 Score 5.1
References
Products affected by CVE-2021-45444
  • Zsh » Zsh » Version: 3.1.5
    cpe:2.3:a:zsh:zsh:3.1.5
  • Zsh » Zsh » Version: 3.1.6
    cpe:2.3:a:zsh:zsh:3.1.6
  • Zsh » Zsh » Version: 3.1.7
    cpe:2.3:a:zsh:zsh:3.1.7
  • Zsh » Zsh » Version: 3.1.8
    cpe:2.3:a:zsh:zsh:3.1.8
  • Zsh » Zsh » Version: 3.1.9
    cpe:2.3:a:zsh:zsh:3.1.9
  • Zsh » Zsh » Version: 4.0.1
    cpe:2.3:a:zsh:zsh:4.0.1
  • Zsh » Zsh » Version: 4.0.2
    cpe:2.3:a:zsh:zsh:4.0.2
  • Zsh » Zsh » Version: 4.0.3
    cpe:2.3:a:zsh:zsh:4.0.3
  • Zsh » Zsh » Version: 4.0.4
    cpe:2.3:a:zsh:zsh:4.0.4
  • Zsh » Zsh » Version: 4.0.5
    cpe:2.3:a:zsh:zsh:4.0.5
  • Zsh » Zsh » Version: 4.0.6
    cpe:2.3:a:zsh:zsh:4.0.6
  • Zsh » Zsh » Version: 4.0.7
    cpe:2.3:a:zsh:zsh:4.0.7
  • Zsh » Zsh » Version: 4.0.8
    cpe:2.3:a:zsh:zsh:4.0.8
  • Zsh » Zsh » Version: 4.0.9
    cpe:2.3:a:zsh:zsh:4.0.9
  • Zsh » Zsh » Version: 4.1.0
    cpe:2.3:a:zsh:zsh:4.1.0
  • Zsh » Zsh » Version: 4.1.1
    cpe:2.3:a:zsh:zsh:4.1.1
  • Zsh » Zsh » Version: 4.2.0
    cpe:2.3:a:zsh:zsh:4.2.0
  • Zsh » Zsh » Version: 4.2.1
    cpe:2.3:a:zsh:zsh:4.2.1
  • Zsh » Zsh » Version: 4.2.2
    cpe:2.3:a:zsh:zsh:4.2.2
  • Zsh » Zsh » Version: 4.2.3
    cpe:2.3:a:zsh:zsh:4.2.3
  • Zsh » Zsh » Version: 4.2.4
    cpe:2.3:a:zsh:zsh:4.2.4
  • Zsh » Zsh » Version: 4.2.5
    cpe:2.3:a:zsh:zsh:4.2.5
  • Zsh » Zsh » Version: 4.2.6
    cpe:2.3:a:zsh:zsh:4.2.6
  • Zsh » Zsh » Version: 4.3.0
    cpe:2.3:a:zsh:zsh:4.3.0
  • Zsh » Zsh » Version: 4.3.1
    cpe:2.3:a:zsh:zsh:4.3.1
  • Zsh » Zsh » Version: 4.3.10
    cpe:2.3:a:zsh:zsh:4.3.10
  • Zsh » Zsh » Version: 4.3.11
    cpe:2.3:a:zsh:zsh:4.3.11
  • Zsh » Zsh » Version: 4.3.12
    cpe:2.3:a:zsh:zsh:4.3.12
  • Zsh » Zsh » Version: 4.3.13
    cpe:2.3:a:zsh:zsh:4.3.13
  • Zsh » Zsh » Version: 4.3.14
    cpe:2.3:a:zsh:zsh:4.3.14
  • Zsh » Zsh » Version: 4.3.15
    cpe:2.3:a:zsh:zsh:4.3.15
  • Zsh » Zsh » Version: 4.3.16
    cpe:2.3:a:zsh:zsh:4.3.16
  • Zsh » Zsh » Version: 4.3.17
    cpe:2.3:a:zsh:zsh:4.3.17
  • Zsh » Zsh » Version: 4.3.2
    cpe:2.3:a:zsh:zsh:4.3.2
  • Zsh » Zsh » Version: 4.3.3
    cpe:2.3:a:zsh:zsh:4.3.3
  • Zsh » Zsh » Version: 4.3.4
    cpe:2.3:a:zsh:zsh:4.3.4
  • Zsh » Zsh » Version: 4.3.5
    cpe:2.3:a:zsh:zsh:4.3.5
  • Zsh » Zsh » Version: 4.3.6
    cpe:2.3:a:zsh:zsh:4.3.6
  • Zsh » Zsh » Version: 4.3.7
    cpe:2.3:a:zsh:zsh:4.3.7
  • Zsh » Zsh » Version: 4.3.8
    cpe:2.3:a:zsh:zsh:4.3.8
  • Zsh » Zsh » Version: 4.3.9
    cpe:2.3:a:zsh:zsh:4.3.9
  • Zsh » Zsh » Version: 5.0.0
    cpe:2.3:a:zsh:zsh:5.0.0
  • Zsh » Zsh » Version: 5.0.1
    cpe:2.3:a:zsh:zsh:5.0.1
  • Zsh » Zsh » Version: 5.0.2
    cpe:2.3:a:zsh:zsh:5.0.2
  • Zsh » Zsh » Version: 5.0.3
    cpe:2.3:a:zsh:zsh:5.0.3
  • Zsh » Zsh » Version: 5.0.4
    cpe:2.3:a:zsh:zsh:5.0.4
  • Zsh » Zsh » Version: 5.0.5
    cpe:2.3:a:zsh:zsh:5.0.5
  • Zsh » Zsh » Version: 5.0.6
    cpe:2.3:a:zsh:zsh:5.0.6
  • Zsh » Zsh » Version: 5.0.7
    cpe:2.3:a:zsh:zsh:5.0.7
  • Zsh » Zsh » Version: 5.0.8
    cpe:2.3:a:zsh:zsh:5.0.8
  • Zsh » Zsh » Version: 5.1
    cpe:2.3:a:zsh:zsh:5.1
  • Zsh » Zsh » Version: 5.1.1
    cpe:2.3:a:zsh:zsh:5.1.1
  • Zsh » Zsh » Version: 5.2
    cpe:2.3:a:zsh:zsh:5.2
  • Zsh » Zsh » Version: 5.3
    cpe:2.3:a:zsh:zsh:5.3
  • Zsh » Zsh » Version: 5.3.1
    cpe:2.3:a:zsh:zsh:5.3.1
  • Zsh » Zsh » Version: 5.4
    cpe:2.3:a:zsh:zsh:5.4
  • Zsh » Zsh » Version: 5.4.1
    cpe:2.3:a:zsh:zsh:5.4.1
  • Zsh » Zsh » Version: 5.4.2
    cpe:2.3:a:zsh:zsh:5.4.2
  • Zsh » Zsh » Version: 5.5
    cpe:2.3:a:zsh:zsh:5.5
  • Zsh » Zsh » Version: 5.5.1
    cpe:2.3:a:zsh:zsh:5.5.1
  • Zsh » Zsh » Version: 5.6
    cpe:2.3:a:zsh:zsh:5.6
  • Zsh » Zsh » Version: 5.6.1
    cpe:2.3:a:zsh:zsh:5.6.1
  • Zsh » Zsh » Version: 5.6.2
    cpe:2.3:a:zsh:zsh:5.6.2
  • Zsh » Zsh » Version: 5.7
    cpe:2.3:a:zsh:zsh:5.7
  • Zsh » Zsh » Version: 5.7.1
    cpe:2.3:a:zsh:zsh:5.7.1
  • Zsh » Zsh » Version: 5.8
    cpe:2.3:a:zsh:zsh:5.8
  • Apple » Mac Os X » Version: 10.15
    cpe:2.3:o:apple:mac_os_x:10.15
  • Apple » Mac Os X » Version: 10.15.1
    cpe:2.3:o:apple:mac_os_x:10.15.1
  • Apple » Mac Os X » Version: 10.15.2
    cpe:2.3:o:apple:mac_os_x:10.15.2
  • Apple » Mac Os X » Version: 10.15.3
    cpe:2.3:o:apple:mac_os_x:10.15.3
  • Apple » Mac Os X » Version: 10.15.4
    cpe:2.3:o:apple:mac_os_x:10.15.4
  • Apple » Mac Os X » Version: 10.15.5
    cpe:2.3:o:apple:mac_os_x:10.15.5
  • Apple » Mac Os X » Version: 10.15.6
    cpe:2.3:o:apple:mac_os_x:10.15.6
  • Apple » Mac Os X » Version: 10.15.7
    cpe:2.3:o:apple:mac_os_x:10.15.7
  • Apple » Macos » Version: 11.0
    cpe:2.3:o:apple:macos:11.0
  • Apple » Macos » Version: 11.0.1
    cpe:2.3:o:apple:macos:11.0.1
  • Apple » Macos » Version: 11.1
    cpe:2.3:o:apple:macos:11.1
  • Apple » Macos » Version: 11.1.0
    cpe:2.3:o:apple:macos:11.1.0
  • Apple » Macos » Version: 11.2
    cpe:2.3:o:apple:macos:11.2
  • Apple » Macos » Version: 11.2.1
    cpe:2.3:o:apple:macos:11.2.1
  • Apple » Macos » Version: 11.3
    cpe:2.3:o:apple:macos:11.3
  • Apple » Macos » Version: 11.3.1
    cpe:2.3:o:apple:macos:11.3.1
  • Apple » Macos » Version: 11.4
    cpe:2.3:o:apple:macos:11.4
  • Apple » Macos » Version: 11.5
    cpe:2.3:o:apple:macos:11.5
  • Apple » Macos » Version: 11.5.1
    cpe:2.3:o:apple:macos:11.5.1
  • Apple » Macos » Version: 11.6
    cpe:2.3:o:apple:macos:11.6
  • Apple » Macos » Version: 11.6.1
    cpe:2.3:o:apple:macos:11.6.1
  • Apple » Macos » Version: 11.6.2
    cpe:2.3:o:apple:macos:11.6.2
  • Apple » Macos » Version: 11.6.3
    cpe:2.3:o:apple:macos:11.6.3
  • Apple » Macos » Version: 11.6.5
    cpe:2.3:o:apple:macos:11.6.5
  • Apple » Macos » Version: 12.0.0
    cpe:2.3:o:apple:macos:12.0.0
  • Apple » Macos » Version: 12.0.1
    cpe:2.3:o:apple:macos:12.0.1
  • Apple » Macos » Version: 12.1
    cpe:2.3:o:apple:macos:12.1
  • Apple » Macos » Version: 12.2
    cpe:2.3:o:apple:macos:12.2
  • Apple » Macos » Version: 12.2.1
    cpe:2.3:o:apple:macos:12.2.1
  • Apple » Macos » Version: 12.3
    cpe:2.3:o:apple:macos:12.3
  • Apple » Macos » Version: 12.3.1
    cpe:2.3:o:apple:macos:12.3.1
  • Debian » Debian Linux » Version: 10.0
    cpe:2.3:o:debian:debian_linux:10.0
  • Debian » Debian Linux » Version: 11.0
    cpe:2.3:o:debian:debian_linux:11.0
  • Debian » Debian Linux » Version: 9.0
    cpe:2.3:o:debian:debian_linux:9.0
  • Fedoraproject » Fedora » Version: 34
    cpe:2.3:o:fedoraproject:fedora:34
  • Fedoraproject » Fedora » Version: 35
    cpe:2.3:o:fedoraproject:fedora:35


Contact Us

Shodan ® - All rights reserved