server/action.py in Fail2ban before 0.8.8 does not properly handle the content of the matches tag, which might allow remote attackers to trigger unsafe behavior in a custom action file via unspecified symbols in this content.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade fail2ban | Jul 30, 2024 | Dec 31, 2012 |
| Suse | — | Upgrade fail2ban | Dec 12, 2013 | Dec 31, 2012 |
| Ubuntu | — | Upgrade fail2ban | Nov 19, 2024 | Dec 31, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub