glances is vulnerable to OS Command Injection
78
High Risk
Glances runs on-alert action commands defined in the configuration file through secure_popen(), which interprets the shell operators &&, | and >. The --disable-config-exec protection that stops operator interpretation for AMP command values is not applied to the on-alert action command path. With --disable-config-exec enabled, a configured alert action still has these operators interpreted, allowing file redirection, command chaining and piping at the privilege of the Glances process when the alert fires. The fix propagates the disable flag into the action command path so operators are no longer interpreted.
You are affected if you are using a version that falls within the vulnerable range and you run Glances with --disable-config-exec and rely on it to neutralise shell operators in configuration-defined on-alert action commands.
glances is vulnerable to OS Command Injection in versions 4.5.5 - 4.5.5.
Upgrade the glances library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant