CVE-2018-1000500
8.1
HIGH
CVSS 3.1
EPSS 0.41%
Description
Busybox contains a Missing SSL certificate validation vulnerability in The "busybox wget" applet that can result in arbitrary code execution. This attack appear to be exploitable via Simply download any file over HTTPS using "busybox wget https://compromised-domain.com/important-file".
How to fix CVE-2018-1000500
To remediate CVE-2018-1000500, upgrade the affected package to a fixed version below.
- Alpine/busybox—upgrade to 1.28.3-r2 or later
- —no fix listed
Is CVE-2018-1000500 being exploited?
Low — EPSS is 0.4%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 1.28.3-r2
- from 0
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.1 | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |