ohmyzsh是一个开源的、社区驱动的框架,用于管理您的zsh配置。 ohmyzsh 存在操作系统命令注入漏洞,该漏洞源于"lib/termsupport.zsh"中定义的"title"函数使用"print"将终端标题设置为用户提供的字符串。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ohmyzsh | ohmyzsh/ohmyzsh | unspecified ~ a263cdac | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2021-3725 | 7.5 HIGH | OS Command Injection in ohmyzsh/ohmyzsh |
| CVE-2021-3727 | 7.5 HIGH | OS Command Injection in ohmyzsh/ohmyzsh |
| CVE-2021-3769 | 7.5 HIGH | OS Command Injection in ohmyzsh/ohmyzsh |
No comments yet