PublicDateAtUSN: 2020-09-09 19:15:00 UTC
Candidate: CVE-2020-24916
PublicDate: 2020-09-09 19:15:00 UTC
References:
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-24916
 https://github.com/erlyaws/yaws/commit/799b3b526d15b7a9bc43ae97165aeb085f18fac1
 https://github.com/vulnbe/poc-yaws-cgi-shell-injection
 https://ubuntu.com/security/notices/USN-4569-1
Description:
 CGI implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable
 to OS command injection.
Ubuntu-Description:
 It was discovered that Yaws mishandled certain input when running CGI scripts.
 A remote attacker could use this vulnerability to execute arbitrary commands.
Notes:
Mitigation:
Bugs:
Priority: medium
Discovered-by:
Assigned-to:
CVSS:
 nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H [9.8 CRITICAL]


Patches_yaws:
upstream_yaws: released (2.0.8+dfsg-1)
precise/esm_yaws: DNE
trusty_yaws: ignored (out of standard support)
trusty/esm_yaws: DNE
xenial_yaws: ignored (end of standard support, was needed)
bionic_yaws: released (2.0.4+dfsg-2ubuntu0.1)
focal_yaws: needed
groovy_yaws: ignored (reached end-of-life)
hirsute_yaws: not-affected (2.0.8+dfsg-1)
impish_yaws: not-affected (2.0.8+dfsg-1)
jammy_yaws: not-affected (2.0.8+dfsg-1)
devel_yaws: not-affected (2.0.8+dfsg-1)
