{"id":"GHSA-7x48-7466-3g33","summary":"Command injection in guake","details":"Guake is a drop-down terminal for GNOME. The package guake before 3.8.5 is vulnerable to Exposed Dangerous Method or Function due to the exposure of execute_command and execute_command_by_uuid methods via the d-bus interface, which makes it possible for a malicious user to run an arbitrary command via the d-bus method. **Note:** Exploitation requires the user to have installed another malicious program that will be able to send dbus signals or run terminal commands.","aliases":["CVE-2021-23556","PYSEC-2022-165","SNYK-PYTHON-GUAKE-2386334"],"modified":"2024-11-30T05:30:24.792328Z","published":"2022-03-18T00:01:11Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2022-03-18T22:40:30Z","nvd_published_at":null,"cwe_ids":[],"severity":"MODERATE"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-23556"},{"type":"WEB","url":"https://github.com/Guake/guake/issues/1796"},{"type":"WEB","url":"https://github.com/Guake/guake/pull/2017"},{"type":"WEB","url":"https://github.com/Guake/guake/commit/b769b3a5fd71a107c58679d217cccc971b4196b4"},{"type":"PACKAGE","url":"https://github.com/Guake/guake"},{"type":"WEB","url":"https://github.com/Guake/guake/releases"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-7x48-7466-3g33"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/guake/PYSEC-2022-165.yaml"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-PYTHON-GUAKE-2386334"}],"affected":[{"package":{"name":"guake","ecosystem":"PyPI","purl":"pkg:pypi/guake"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.8.5"}]}],"versions":["3.0.0","3.0.0.0b2","3.0.1","3.0.2","3.0.3","3.0.4","3.0.5","3.0.6","3.1.0","3.1.1","3.2.0","3.2.1","3.2.1.dev35","3.2.2","3.3.0","3.3.1","3.3.2","3.3.3","3.4.0","3.5.0","3.6.0","3.6.1","3.6.2","3.6.3","3.7.0","3.8.2.0rc2.dev0","3.8.2.0rc3.dev0","3.8.3.dev0","3.8.4.dev0","3.8.5.0rc2","3.8.5.dev0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/03/GHSA-7x48-7466-3g33/GHSA-7x48-7466-3g33.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:L"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N"}]}