Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The Trigger plugin in bcfg2 1.2.x before 1.2.3 allows remote attackers with root access to the client to execute arbitrary commands via shell metacharacters in the UUID field to the server process (bcfg2-server).
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Bcfg2 ‘Trigger’插件远程命令注入漏洞
Vulnerability Description
Bcfg2提供给系统管理员一个一致性的、可再生的、可核查的环境,并提供可视化的报告工具,以协助日常的行政工作。 Bcfg2 1.2.3之前的1.2.x版本中存在远程命令注入漏洞,该漏洞源于在‘Trigger’插件中对用户提供的的输入未经正确验证。攻击者可利用该漏洞在受影响应用程序上下文中注入和执行任意命令,且有助于完全操控系统。
CVSS Information
N/A
Vulnerability Type
N/A