Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An improper limitation of path name flaw was found in containernetworking/cni in versions before 0.8.1. When specifying the plugin to load in the 'type' field in the network configuration, it is possible to use special elements such as "../" separators to reference binaries elsewhere on the system. This flaw allows an attacker to execute other existing binaries other than the cni plugins/types, such as 'reboot'. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
CVSS Information
N/A
Vulnerability Type
输入验证不恰当
Vulnerability Title
Cloud Native Computing Foundation CNI 路径遍历漏洞
Vulnerability Description
Cloud Native Computing Foundation CNI是Cloud Native Computing Foundation基金会的一个用于为Linux环境的容器提供网络支撑的插件。该应用仅涉及容器的网络连接以及删除容器时删除分配的资源。 Cloud Native Computing Foundation CNI 中存在路径遍历漏洞,该漏洞源于用户输入构造命令、数据结构或记录的操作过程中,网络系统或产品缺乏对用户输入数据的正确验证,未过滤或未正确过滤掉其中的特殊元素,导致系统或产品产生解
CVSS Information
N/A
Vulnerability Type
N/A