CVE-2022-45639

Source
https://cve.org/CVERecord?id=CVE-2022-45639
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-45639.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-45639
Published
2023-01-24T02:15:09.817Z
Modified
2026-04-10T04:52:29.724829Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

OS Command injection vulnerability in sleuthkit fls tool 4.11.1 allows attackers to execute arbitrary commands via a crafted value to the m parameter. NOTE: third parties have disputed this because there is no analysis showing that the backtick command executes outside the context of the user account that entered the command line.

References

Affected packages

Git / github.com/sleuthkit/sleuthkit

Affected ranges

Type
GIT
Repo
https://github.com/sleuthkit/sleuthkit
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "4.11.1"
        }
    ]
}

Affected versions

sleuthkit-4.*
sleuthkit-4.0.2
sleuthkit-4.11.1
sleuthkit-4.6.3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-45639.json"