obsidian-dataview是一个应用软件。一个复杂的查询语言实现黑曜石笔记记录工具。 Obsidian Dataview 0.4.12-hotfix1之前版本存在安全漏洞,该漏洞源于软件对于eval函数缺少有效的限制与过滤,导致攻击者可以进行eval注入,软件执行用户输入的evalInContext函数。攻击者可利用该漏洞编写恶意Markdown文件,一旦打开该文件,该文件将执行任意代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
VULNERABLE: eval injection — malicious markdown inline query executed arbitrary code, proof token PROOF_1087dc25322cc431 exfiltrated
| CVE-2021-43400 | BlueZ 资源管理错误漏洞 | |
| CVE-2020-25367 | D-Link DIR-823G 命令注入漏洞 | |
| CVE-2020-25366 | D-Link DIR-823G 安全漏洞 | |
| CVE-2020-25368 | D-Link DIR-823G 命令注入漏洞 | |
| CVE-2021-42624 | Miniftpd 安全漏洞 | |
| CVE-2021-43281 | MyBB 代码注入漏洞 | |
| CVE-2021-43293 | Sonatype Nexus Repository 代码问题漏洞 | |
| CVE-2021-43389 | Linux kernel 缓冲区错误漏洞 | |
| CVE-2020-21139 | EC Cloud E-Commerce System 跨站请求伪造漏洞 | |
| CVE-2021-43396 | GNU C Library 安全漏洞 | |
| CVE-2021-43398 | Crypto++ 安全漏洞 |
No comments yet