Loading HuntDB...

GHSA-3vrr-vhcq-w4wm

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

Improper Neutralization of Special Elements used in a Command ('Command Injection') in ePO extension in McAfee Data Loss Prevention (DLP) 11.x prior to 11.3.0 allows Authenticated Adminstrator to execute arbitrary code with their local machine privileges via a specially crafted DLP policy, which is exported and opened on the their machine. In our checks, the user must explicitly allow the code to execute.

Related CVEs

Key Information

GHSA ID
GHSA-3vrr-vhcq-w4wm
Published
May 24, 2022 4:51 PM
Last Modified
May 24, 2022 4:51 PM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: September 14, 2025 6:31 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.