Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
A security-check flaw was found in the way the Heketi 5 server API handled user requests. An authenticated Heketi user could send specially crafted requests to the Heketi server, resulting in remote command execution as the user running Heketi server and possibly privilege escalation.
CVSS Information
N/A
Vulnerability Type
OS命令中使用的特殊元素转义处理不恰当(OS命令注入)
Vulnerability Title
Heketi 操作系统命令注入漏洞
Vulnerability Description
Heketi是一款基于REST的GlusterFS管理框架,它提供了一个RESTful管理界面,可以用来管理GlusterFS的生命周期。 Heketi 5 server API存在操作系统命令注入漏洞。攻击者利用该漏洞可以执行远程命令,并提升权限。
CVSS Information
N/A
Vulnerability Type
N/A