Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Sandstorm before build 0.203 allows remote attackers to read any specified file under /etc or /run via the sandbox backup function. The root cause is that the findFilesToZip function doesn't filter Line Feed (\n) characters in a directory name.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Sandstorm 安全漏洞
Vulnerability Description
Sandstorm是一套个人云平台。该平台具有文件存储、应用程序管理、任务和项目管理等功能。 Sandstorm build 0.203之前版本中存在安全漏洞,该漏洞源于‘findFilesToZip’函数没有过滤目录名称中的换行(\n)字符。远程攻击者可借助沙盒的备份函数利用该漏洞读取/etc或/run下的任意文件。
CVSS Information
N/A
Vulnerability Type
N/A