CVE-2018-5702
Transmission through 2.92 relies on X-Transmission-Session-Id (which is not a forbidden header for Fetch) for access control, which allows remote attackers to execute arbitrary RPC commands, and consequently write to arbitrary files, via POST requests…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 11.9%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
Transmission through 2.92 relies on X-Transmission-Session-Id (which is not a forbidden header for Fetch) for access control, which allows remote attackers to execute arbitrary RPC commands, and consequently write to arbitrary files, via POST requests to /transmission/rpc in conjunction with a DNS rebinding attack.
- CVSS 3.0
- 8.8 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 11.93% probability · 96th percentile
- CISA KEV
- Not listed
- Affected
- transmissionbt/transmission · debian/debian linux
- Source
- cve@mitre.org
References
- https://bugs.chromium.org/p/project-zero/issues/detail?id=1447Exploit, Issue Tracking, Technical Description, Third Party Advisory
- https://github.com/transmission/transmission/pull/468Exploit, Technical Description, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/01/msg00020.htmlMailing List, Third Party Advisory
- https://security.gentoo.org/glsa/201806-07Third Party Advisory
- https://twitter.com/taviso/status/951526615145566208Third Party Advisory
- https://www.debian.org/security/2018/dsa-4087Third Party Advisory
- https://www.exploit-db.com/exploits/43665/Exploit, Third Party Advisory, VDB Entry
- https://bugs.chromium.org/p/project-zero/issues/detail?id=1447Exploit, Issue Tracking, Technical Description, Third Party Advisory
- https://github.com/transmission/transmission/pull/468Exploit, Technical Description, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/01/msg00020.htmlMailing List, Third Party Advisory
- https://security.gentoo.org/glsa/201806-07Third Party Advisory
- https://twitter.com/taviso/status/951526615145566208Third Party Advisory
- https://www.debian.org/security/2018/dsa-4087Third Party Advisory
- https://www.exploit-db.com/exploits/43665/Exploit, Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.