Duplicate Advisory: Permissive Regular Expression in tacquito
Critical severity
GitHub Reviewed
Published
Oct 17, 2024
to the GitHub Advisory Database
•
Updated Nov 1, 2024
Withdrawn
This advisory was withdrawn on Nov 1, 2024
Package
Affected versions
< 0.0.0-20241011192817-07b49d1358e6
Patched versions
0.0.0-20241011192817-07b49d1358e6
Description
Published by the National Vulnerability Database
Oct 17, 2024
Published to the GitHub Advisory Database
Oct 17, 2024
Reviewed
Nov 1, 2024
Withdrawn
Nov 1, 2024
Last updated
Nov 1, 2024
Tacquito prior to commit 07b49d1358e6ec0b5aa482fcd284f509191119e2 was not properly performing regex matches on authorized commands and arguments. Configured allowed commands/arguments were intended to require a match on the entire string, but instead only enforced a match on a sub-string. That would have potentially allowed unauthorized commands to be executed.
References