VDB

CVE-2020-17367

CVE-2020-17367 PUBLISHED CVSS 7.800000190734863 HIGH

Firejail through 0.9.62 does not honor the -- end-of-options indicator after the --output option, which may lead to command injection.

EPSS 1.46% · 72.7th percentile

Risk Scores

CVSS 3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
1.46%
72.7th percentile

Affected Products

VendorProductVersions
Ubuntu:20.04:LTSfirejail0.9.60-2, 0, 0.9.62-3ubuntu0.1
Ubuntu:18.04:LTSfirejail0.9.52-1, 0, 0.9.50-3
Ubuntu:16.04:LTSfirejail0, 0.9.38-1ubuntu0.1, 0.9.32-1

Timeline

  • Aug 11, 2020 CVE Published
  • Apr 14, 2021 EPSS Score
  • Jun 23, 2021 EPSS Score
  • Aug 25, 2021 EPSS Score
  • Dec 29, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Mar 2, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • May 4, 2022 EPSS Score
  • Sep 9, 2022 EPSS Score
  • Nov 11, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›