Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The Square Squash allows remote attackers to execute arbitrary code via a YAML document in the (1) namespace parameter to the deobfuscation function or (2) sourcemap parameter to the sourcemap function in app/controllers/api/v1_controller.rb.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Square Squash 代码注入漏洞
Vulnerability Description
Square Squash是美国Square公司的一套异常报告和缺陷分析工具。该工具提供数据图表分析、代码分析和Bug跟踪等功能。 Square Squash的app/controllers/api/v1_controller.rb文件中的‘deobfuscation’和‘sourcemap’函数存在安全漏洞。远程攻击者可借助YAML文档利用该漏洞执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A