CVE-2014-8990: Debian Linux
High severity, CVSS 7.5. EPSS: 5.2% chance of exploitation in the next 30 days.
default-rsyncssh.lua in Lsyncd 2.1.5 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in a filename.
Affected products
- Debian Debian Linux: version 7.0 only
- Fedoraproject Fedora: version 19 only; version 20 only
- Lsyncd Project Lsyncd: up to and including 2.1.5
Published 2014-12-05. Last modified 2026-06-17.