Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-1037 | FitNesse all releases allows a remote authenticated attacker to execute arbitrary OS commands. Note: A contributor of FitNesse has claimed that this is not a vulnerability but a product specification and this is currently under further investigation. |
Github GHSA |
GHSA-x9r9-48rm-4xm6 | FitNesse allows execution of arbitrary OS commands |
Fri, 19 Sep 2025 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-77 |
Thu, 10 Oct 2024 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | FitNesse all releases allows a remote authenticated attacker to execute arbitrary OS commands. | FitNesse all releases allows a remote authenticated attacker to execute arbitrary OS commands. Note: A contributor of FitNesse has claimed that this is not a vulnerability but a product specification and this is currently under further investigation. |
| First Time appeared |
Fitnesse
Fitnesse fitnesse |
|
| Weaknesses | CWE-78 | |
| CPEs | cpe:2.3:a:fitnesse:fitnesse:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Fitnesse
Fitnesse fitnesse |
|
| Metrics |
ssvc
|
Wed, 28 Aug 2024 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-77 | |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: jpcert
Published:
Updated: 2025-09-19T17:24:24.131Z
Reserved: 2024-03-06T08:57:22.986Z
Link: CVE-2024-28125
Updated: 2024-08-02T00:48:48.830Z
Status : Deferred
Published: 2024-03-18T08:15:06.347
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-28125
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA