CVE-2024-52010
Last modified
CVE-2024-52010 is a high-severity vulnerability rated 8.6/10 on the CVSS scale. Zoraxy is a general purpose HTTP reverse proxy and forwarding tool. A command injection vulnerability in the Web SSH feature allows an authenticated attacker to execute arbitrary commands as root on the host. EPSS estimates a 1.44% chance of exploitation in the next 30 days.
Description
Zoraxy is a general purpose HTTP reverse proxy and forwarding tool. A command injection vulnerability in the Web SSH feature allows an authenticated attacker to execute arbitrary commands as root on the host. Zoraxy has a Web SSH terminal feature that allows authenticated users to connect to SSH servers from their browsers. In HandleCreateProxySession the request to create an SSH session is handled. An attacker can exploit the username variable to escape from the bash command and inject arbitrary commands into sshCommand. This is possible, because, unlike hostname and port, the username is not validated or sanitized.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-52010?
How severe is CVE-2024-52010?
How do I fix CVE-2024-52010?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-52005Git is a source code management tool. When cloning from a se…8.8
- CVE-2024-52006Git is a fast, scalable, distributed revision control system…7.5
- CVE-2024-52007HAPI FHIR is a complete implementation of the HL7 FHIR stand…8.6
- CVE-2024-52008Fides is an open-source privacy engineering platform. The us…8.8
- CVE-2024-52009Atlantis is a self-hosted golang application that listens fo…9.8
- CVE-2024-5201Privilege Escalation in OpenText Dimensions RM allows an aut…8.8
- CVE-2024-52011launch-editor allows users to open files with line numbers i…8.3
- CVE-2024-52012Relative Path Traversal vulnerability in Apache Solr. Solr …5.4
- CVE-2024-52013Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154…5.7
- CVE-2024-52014Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154…5.7
- CVE-2024-52015Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154…5.7
- CVE-2024-52016Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154…5.7
Are you affected by CVE-2024-52010?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
