Loading HuntDB...

GHSA-5jw9-5ff9-vr5p

GitHub Security Advisory

⚠ Unreviewed HIGH Has CVE

Advisory Details

DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in the NetworkManager integration script included in the DHCP client. A malicious DHCP server, or an attacker on the local network able to spoof DHCP responses, could use this flaw to execute arbitrary commands with root privileges on systems using NetworkManager and configured to obtain network configuration using the DHCP protocol.

Related CVEs

Key Information

GHSA ID
GHSA-5jw9-5ff9-vr5p
Published
May 13, 2022 1:49 AM
Last Modified
May 13, 2022 1:49 AM
CVSS Score
7.5 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: June 15, 2025 6:24 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.