ohmyzsh是一个开源的、社区驱动的框架,用于管理您的zsh配置。 ohmyzsh 存在操作系统命令注入漏洞,该漏洞源于通过按Alt-Left和Alt-Right触发的在目录历史记录中前后移动的小部件使用对目录名称不安全地执行eval的函数。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ohmyzsh | ohmyzsh/ohmyzsh | unspecified ~ 06fc5fb | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2021-3726 | 7.5 HIGH | OS Command Injection in ohmyzsh/ohmyzsh |
| CVE-2021-3727 | 7.5 HIGH | OS Command Injection in ohmyzsh/ohmyzsh |
| CVE-2021-3769 | 7.5 HIGH | OS Command Injection in ohmyzsh/ohmyzsh |
No comments yet