VDB

CVE-2022-3008

CVE-2022-3008 PUBLISHED CVSS 8.100000381469727 HIGH

The tinygltf library uses the C library function wordexp() to perform file path expansion on untrusted paths that are provided from the input file. This function allows for command injection by using backticks. An attacker could craft an untrusted path input that would result in a path expansion. We recommend upgrading to 2.6.0 or past commit 52ff00a38447f06a17eab1caa2cf0730a119c751

EPSS 3.03% · 86.6th percentile

Risk Scores

CVSS 3.1
8.100000381469727
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
EPSS Score
3.03%
86.6th percentile

Affected Products

VendorProductVersions
tinygltf_projecttinygltf0
syoyotinygltfunspecified
debiandebian_linux11.0

Timeline

  • Sep 5, 2022 CVE Published
  • Sep 6, 2022 EPSS Score
  • Oct 21, 2022 EPSS Score
  • Jan 20, 2023 EPSS Score
  • Mar 6, 2023 EPSS Score
  • Apr 21, 2023 EPSS Score
  • Jul 20, 2023 EPSS Score
  • Oct 19, 2023 EPSS Score
  • Dec 3, 2023 EPSS Score
  • Mar 3, 2024 EPSS Score
  • Jun 2, 2024 EPSS Score
  • Sep 1, 2024 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›