Vulnerabilities > CVE-2023-38198 - Unspecified vulnerability in Acme.Sh Project Acme.Sh

047910
CVSS 9.8 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
acme-sh-project
critical

Summary

acme.sh before 3.0.6 runs arbitrary commands from a remote server via eval, as exploited in the wild in June 2023.