Back

CVE-2019-5029

CRITICAL

An exploitable command injection vulnerability exists in the Config editor of the Exhibitor Web UI versions 1.0.9 to 1.7.1. Arbitrary shell commands surrounded by backticks or $() can be inserted into the editor and will be executed by the Exhibitor process when it launches ZooKeeper. An attacker can execute any command as the user running the Exhibitor process.

Published: Nov 13, 2019 Modified: Jun 17, 2026
CWE-78 CWE-78

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (1)

Vendor Product Version
exhibitor_project exhibitor * ≥ 1.0.9

GitHub Security Advisory GHSA-vq4h-pfrp-qjjj

An exploitable command injection vulnerability exists in the Config editor of the Exhibitor Web...

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 57.15%

Top 1% most likely to be exploited

Threat Score 56.3 / 100

Data Sources

NVD EPSS GitHub