CVE-2020-15167

Source
https://cve.org/CVERecord?id=CVE-2020-15167
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-15167.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2020-15167
Aliases
  • GHSA-mw2v-4q78-j2cw
Downstream
Related
Published
2020-09-02T18:15:11.313Z
Modified
2026-07-09T00:06:39.883784Z
Severity
  • 8.6 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

In Miller (command line utility) using the configuration file support introduced in version 5.9.0, it is possible for an attacker to cause Miller to run arbitrary code by placing a malicious .mlrrc file in the working directory. See linked GitHub Security Advisory for complete details. A fix is ready and will be released as Miller 5.9.1.

References

Affected packages

Git / github.com/johnkerl/miller

Affected ranges

Type
GIT
Repo
https://github.com/johnkerl/miller
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "5.9.0"
        },
        {
            "last_affected": "5.9.0"
        }
    ],
    "source": "CPE_STRING",
    "cpe": "cpe:2.3:a:johnkerl:miller:5.9.0:*:*:*:*:*:*:*"
}

Affected versions

5.*
5.9.0
v5.*
v5.9.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-15167.json"