Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
In ONOS 1.15.0, apps/yang/web/src/main/java/org/onosproject/yang/web/YangWebResource.java mishandles backquote characters within strings that can be used in a shell command.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
ONOS 代码问题漏洞
Vulnerability Description
ONOS是美国Linux基金会的一套开源的SDN网络操作系统。 ONOS 1.15.0版本中存在安全漏洞,该漏洞源于apps/yang/web/src/main/java/org/onosproject/yang/web/YangWebResource.java文件没有正确处理字符串中的反引号,而该字符串会被用于shell命令中。攻击者可借助特制的输入利用该漏洞执行任意命令。
CVSS Information
N/A
Vulnerability Type
N/A