Qualys discovered that needrestart, before version 3.8, passes unsanitized data to a library (Modules::ScanDeps) which expects safe input. This could allow a local attacker to execute arbitrary shell commands. Please see the related CVE-2024-10224 in Modules::ScanDeps.
CVE ID: CVE-2024-11003
CVSS Base Severity: HIGH
CVSS Base Score: 7.8
Vendor: needrestart
Product: needrestart
EPSS Score: 0.05% (probability of being exploited)
EPSS Percentile: 19.32% (scored less or equal to compared to others)
EPSS Date: 2025-02-03 (when was this score calculated)