PatchSiren

Sociomantic CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL Sociomantic CVE published 2017-01-19

CVE-2016-7794

CVE-2016-7794 is a critical remote code execution vulnerability in sociomantic-tsunami git-hub affecting versions through 0.10.2. The supplied description says a remote attacker can execute arbitrary code by using a crafted repository name. Because the issue is network-reachable and requires no user interaction, it should be treated as an emergency for any exposed deployment.

HIGH Sociomantic CVE published 2017-01-19

CVE-2016-7793

CVE-2016-7793 is a high-severity vulnerability in sociomantic-tsunami git-hub versions before 0.10.3. According to the NVD record, a remote attacker can execute arbitrary code by supplying a crafted repository URL. The NVD entry also maps the issue to CWE-284 and rates it CVSS 3.0 8.8 (AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H), indicating broad impact if the vulnerable code path is reachable.