CVSS v3
9.8
CRITICAL
EPSS Score
90.0 %
exploit probability
CISA KEV
No
known exploited
Exploitation
—
SSVC status
Description
Aerospike Community Edition 4.9.0.5 allows for unauthenticated submission and execution of user-defined functions (UDFs), written in Lua, as part of a database query. It attempts to restrict code execution by disabling os.execute() calls, but this is insufficient. Anyone with network access can use a crafted UDF to execute arbitrary OS commands on all nodes of the cluster at the permission level of the user running the Aerospike service.
Technical details
- Published
- 2020-08-05
- Exploit-DB
- EDB-49067
Frequently asked questions
What is CVE-2020-13151?
Aerospike Community Edition 4.9.0.5 allows for unauthenticated submission and execution of user-defined functions (UDFs), written in Lua, as part of a database query. It attempts to restrict code execution by disabling os.execute() calls, but this is insufficient. Anyone with network access can use a crafted UDF to execute arbitrary OS commands on all nodes of the cluster at the permission level of the user running the Aerospike service.
Is CVE-2020-13151 actively exploited?
Active exploitation of CVE-2020-13151 has not been confirmed. The EPSS score is 90.0%, indicating the estimated probability of exploitation in the next 30 days.
What is the CVSS score for CVE-2020-13151?
CVE-2020-13151 has a CVSS v3 base score of 9.8 (CRITICAL severity).
Is CVE-2020-13151 affecting your environment?
Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.
No credit card required · 500 free checks/month · Free API key
Other 2020 vulnerabilities worth triaging
Ranked by exploit probability (EPSS).