CVE-2024-42002
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Summary
A code injection vulnerability has been discovered in the Robot Operating System 2 (ROS 2) 'ros2topic' command-line tool, affecting all ROS 2 distributions from Crystal Clemmys up to and including Lyrical Luth and Rolling Ridley. The vulnerability lies in the 'hz' verb, which reports the publishing rate of a topic and accepts a user-provided Python expression via the –filter option. This input is passed directly to the eval() function without sanitization, allowing a local user to craft and execute arbitrary code.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Open Source Robotics Foundation | Robot Operating System 2 (ROS 2) | Rolling Ridley | affected |
| Open Source Robotics Foundation | Robot Operating System 2 (ROS 2) | Lyrical Luth | affected |
| Open Source Robotics Foundation | Robot Operating System 2 (ROS 2) | Kilted Kaiju | affected |
| Open Source Robotics Foundation | Robot Operating System 2 (ROS 2) | Jazzy Jalisco | affected |
| Open Source Robotics Foundation | Robot Operating System 2 (ROS 2) | Iron Irwini | affected |
| Open Source Robotics Foundation | Robot Operating System 2 (ROS 2) | Humble Hawksbill | affected |
| Open Source Robotics Foundation | Robot Operating System 2 (ROS 2) | Galactic Geochelone | affected |
| Open Source Robotics Foundation | Robot Operating System 2 (ROS 2) | Foxy Fitzroy | affected |
| Open Source Robotics Foundation | Robot Operating System 2 (ROS 2) | Eloquent Elusor | affected |
| Open Source Robotics Foundation | Robot Operating System 2 (ROS 2) | Dashing Diademata | affected |
| Open Source Robotics Foundation | Robot Operating System 2 (ROS 2) | Crystal Clemmys | affected |
Weaknesses
- CWE-95: CWE-95 Improper neutralization of directives in dynamically evaluated code ('eval injection')
- CWE-94: CWE-94 Improper Control of Generation of Code ('Code Injection')
Workarounds
Do not pass untrusted or unreviewed input to the –filter option of 'ros2 topic hz'.
References
- https://github.com/ros2/ros2cli/pull/1001
- https://github.com/ros2/ros2cli/pull/133#discussion_r223081766
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.