CVE-2015-1815: Fedoraproject Fedora
High severity, CVSS 10.0. EPSS: 16.5% chance of exploitation in the next 30 days.
The get_rpm_nvr_by_file_path_temporary function in util.py in setroubleshoot before 3.2.22 allows remote attackers to execute arbitrary commands via shell metacharacters in a file name.
Affected products
- Fedoraproject Fedora: version 22 only
- Selinux Setroubleshoot: up to and including 3.2.21
Published 2015-03-30. Last modified 2026-06-17.