Critical severity9.8NVD Advisory· Published Oct 6, 2023· Updated Jun 17, 2026
CVE-2023-45239
CVE-2023-45239
Description
A lack of input validation exists in tac_plus prior to commit 4fdf178 which, when pre or post auth commands are enabled, allows an attacker who can control the username, rem-addr, or NAC address sent to tac_plus to inject shell commands and gain remote code execution on the tac_plus server.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*
- Meta/tac_plusv5Range: 0
Patches
Vulnerability mechanics
References
3- github.com/facebook/tac_plus/pull/41nvdExploitPatch
- github.com/facebook/tac_plus/security/advisories/GHSA-p334-5r3g-4vx3nvdVendor Advisory
- lists.fedoraproject.org/archives/list/[email protected]/message/X4J7ZYMFZB4G4OU5EDJPQLP6F6RKDGIH/nvdMailing ListThird Party Advisory
News mentions
0No linked articles in our index yet.