Peering Manager is a BGP session management tool. There is a Server Side Template Injection vulnerability that leads to Remote Code Execution in Peering Manager <=1.8.2. As a result arbitrary commands can be executed on the operating system that is running Peering Manager. This issue has been addressed in version 1.8.3. Users are advised to upgrade. There are no known workarounds for this vulnerability.
History

Thu, 20 Feb 2025 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Peering-manager
Peering-manager peering Manager
Weaknesses NVD-CWE-Other
CPEs cpe:2.3:a:peering-manager:peering_manager:*:*:*:*:*:*:*:*
Vendors & Products Peering-manager
Peering-manager peering Manager

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-08-28T16:23:15.497Z

Reserved: 2024-03-04T14:19:14.059Z

Link: CVE-2024-28114

cve-icon Vulnrichment

Updated: 2024-08-02T00:48:49.295Z

cve-icon NVD

Status : Analyzed

Published: 2024-03-12T20:15:08.113

Modified: 2025-02-20T17:18:20.863

Link: CVE-2024-28114

cve-icon Redhat

No data.