CVE-2023-30856

Source
https://cve.org/CVERecord?id=CVE-2023-30856
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-30856.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-30856
Aliases
  • GHSA-q8xc-f2wf-ffh9
Published
2023-04-28T15:54:54.891Z
Modified
2026-04-02T08:57:15.656466Z
Severity
  • 8.3 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L CVSS Calculator
Summary
eDEX-UI cross-site websocket hijacking vulnerability enables remote command execution
Details

eDEX-UI is a science fiction terminal emulator. Versions 2.2.8 and prior are vulnerable to cross-site websocket hijacking. When running eDEX-UI and browsing the web, a malicious website can connect to eDEX's internal terminal control websocket, and send arbitrary commands to the shell. The project has been archived since 2021, and as of time of publication there are no plans to patch this issue and release a new version. Some workarounds are available, including shutting down eDEX-UI when browsing the web and ensuring the eDEX terminal runs with lowest possible privileges.

Database specific
{
    "cwe_ids": [
        "CWE-1385",
        "CWE-346"
    ],
    "cna_assigner": "GitHub_M",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/30xxx/CVE-2023-30856.json"
}
References

Affected packages

Git / github.com/gitsquared/edex-ui

Affected ranges

Type
GIT
Repo
https://github.com/gitsquared/edex-ui
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.2.8"
        }
    ]
}

Affected versions

v0.*
v0.1.0
v0.5.0
v0.6.0
v0.7.0
v0.7.1
v0.7.2
v0.7.3
v0.7.4
v0.8.0
v0.8.1
v0.9.0
v0.9.1
v1.*
v1.0.0
v1.0.0-rc1
v1.0.0-rc2
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v2.*
v2.0.0
v2.0.1
v2.1.0
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.2.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-30856.json"