Brook is a cross-platform programmable network tool. The `tproxy` server is vulnerable to a drive-by command injection. An attacker may fool a victim into visiting a malicious web page which will trigger requests to the local `tproxy` service leading to remote code execution. A patch is available in version 20230606.
References
Configurations
History
No history.
Information
Published : 2023-06-01 15:15
Updated : 2023-06-09 13:31
NVD link : CVE-2023-33965
Mitre link : CVE-2023-33965
CVE.ORG link : CVE-2023-33965
JSON object : View
Products Affected
txthinking
- brook
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')