CVE-2020-11016 CRITICAL

CVE-2020-11016: Remote code execution in Message sending functionality in IntelMQ Manager

Vendor Certtools
Product IntelMQ Manager
Weakness CWE-78
Published April 30, 2020
Last update August 4, 2024

CVSS base score

9.1/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality Low
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:L

What the vulnerability does

01Description

IntelMQ Manager from version 1.1.0 and before version 2.1.1 has a vulnerability where the backend incorrectly handled messages given by user-input in the "send" functionality of the Inspect-tool of the Monitor component. An attacker with access to the IntelMQ Manager could possibly use this issue to execute arbitrary code with the privileges of the webserver. Version 2.1.1 fixes the vulnerability.

Key dates

02Disclosure timeline

April 30, 2020 CVE published
August 4, 2024 Record updated