Loading HuntDB...

GHSA-gpc3-vjh4-7wm2

GitHub Security Advisory

⚠ Unreviewed HIGH Has CVE

Advisory Details

There is a command injection vulnerability in CMA service module of FusionCompute product when processing the default certificate file. The software constructs part of a command using external special input from users, but the software does not sufficiently validate the user input. Successful exploit could allow the attacker to inject certain commands to the system. Affected product versions include: FusionCompute 6.0.0, 6.3.0, 6.3.1, 6.5.0, 6.5.1, 8.0.0.

Related CVEs

Key Information

GHSA ID
GHSA-gpc3-vjh4-7wm2
Published
November 24, 2021 12:00 AM
Last Modified
February 28, 2024 12:02 AM
CVSS Score
7.5 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: August 1, 2025 6:44 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.