VDB

CVE-2021-23422

CVE-2021-23422 PUBLISHED CVSS 7.800000190734863 HIGH

This affects the package bikeshed before 3.0.0. This can occur when an untrusted source file containing Inline Tag Command metadata is processed. When an arbitrary OS command is executed, the command output would be included in the HTML output.

EPSS 0.79% · 53.7th percentile

Risk Scores

CVSS 3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
0.79%
53.7th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSbikeshed1.72-0ubuntu1, 0, 1.71-0ubuntu1
Ubuntu:16.04:LTSbikeshed1.62-0ubuntu1, 1.65-0ubuntu1, 1.60-0ubuntu1
Ubuntu:25.10bikeshed0, 1.78-0ubuntu1
Ubuntu:24.04:LTSbikeshed1.78-0ubuntu1, 0
Ubuntu:20.04:LTSbikeshed0, 1.78-0ubuntu1
Ubuntu:22.04:LTSbikeshed0, 1.78-0ubuntu1

Timeline

  • Aug 16, 2021 EPSS Score
  • Aug 16, 2021 CVE Published
  • Oct 14, 2021 EPSS Score
  • Dec 11, 2021 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Feb 8, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • Apr 8, 2022 EPSS Score
  • Jun 5, 2022 EPSS Score
  • Aug 4, 2022 EPSS Score
  • Nov 30, 2022 EPSS Score
  • Jan 27, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›