Vulnerability   
Search   
    Search 219043 CVE descriptions
and 99761 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.103774
Category:Web application abuses
Title:Graphite Remote Code Execution Vulnerability
Summary:Graphite is prone to a remote code-execution vulnerability.
Description:Summary:
Graphite is prone to a remote code-execution vulnerability.

Vulnerability Insight:
In graphite-web 0.9.5, a 'clustering' feature was introduced to
allow for scaling for a graphite setup. This was achieved by passing pickles
between servers. However due to no explicit safety measures having been
implemented to limit the types of objects that can be unpickled, this creates
a condition where arbitrary code can be executed

Vulnerability Impact:
Successfully exploiting this issue will allow attackers to execute
arbitrary code within the context of the application.

Affected Software/OS:
Graphite versions 0.9.5 through 0.9.10 are vulnerable.

Solution:
Ask the Vendor for an update.

CVSS Score:
6.8

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:P

Cross-Ref: BugTraq ID: 61894
Common Vulnerability Exposure (CVE) ID: CVE-2013-5093
http://www.securityfocus.com/bid/61894
http://www.exploit-db.com/exploits/27752
http://ceriksen.com/2013/08/20/graphite-remote-code-execution-vulnerability-advisory/
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/unix/webapp/graphite_pickle_exec.rb
http://www.osvdb.org/96436
http://secunia.com/advisories/54556
CopyrightCopyright (C) 2013 Greenbone Networks GmbH

This is only one of 99761 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2024 E-Soft Inc. All rights reserved.