Adam Bell discovered that Trove incorrectly handled arguments to the backup command. A remote attacker could possibly use this issue to execute arbitrary code.
{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "python3-trove",
"binary_version": "2:17.0.0-0ubuntu1.1"
},
{
"binary_name": "trove-api",
"binary_version": "2:17.0.0-0ubuntu1.1"
},
{
"binary_name": "trove-common",
"binary_version": "2:17.0.0-0ubuntu1.1"
},
{
"binary_name": "trove-conductor",
"binary_version": "2:17.0.0-0ubuntu1.1"
},
{
"binary_name": "trove-guestagent",
"binary_version": "2:17.0.0-0ubuntu1.1"
},
{
"binary_name": "trove-taskmanager",
"binary_version": "2:17.0.0-0ubuntu1.1"
}
]
}