In Vim before 8.1.0881, users can circumvent the rvim restricted mode and execute arbitrary OS commands via scripting interfaces (e.g., Python, Ruby, or Lua).
2020-05-28T14:15:11.563
2024-11-21T04:39:24.670
Modified
CVSSv3.1: 5.3 (MEDIUM)
AV:L/AC:L/Au:N/C:P/I:P/A:P
3.9
6.4
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | vim | vim | < 8.1.0881 | Yes |
| Operating System | debian | debian_linux | 9.0 | Yes |
| Operating System | opensuse | leap | 15.1 | Yes |
| Operating System | canonical | ubuntu_linux | 16.04 | Yes |
| Operating System | canonical | ubuntu_linux | 18.04 | Yes |
| Operating System | apple | mac_os_x | 10.13.6 | Yes |
| Operating System | apple | mac_os_x | 10.14.6 | Yes |
| Application | starwindsoftware | command_center | 2 | Yes |
| Application | starwindsoftware | san_\&_nas | 1.0 | Yes |