Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%
Get alerts for future matching vulnerabilitiesLog in to subscribe
I. Basic Information for CVE-2024-11662
Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
welliamcao OpsManage API Endpoint deploy_api.py deploy_host_vars deserialization
Source: NVD (National Vulnerability Database)
Vulnerability Description
A vulnerability was found in welliamcao OpsManage 3.0.1/3.0.2/3.0.3/3.0.4/3.0.5. It has been rated as critical. This issue affects the function deploy_host_vars of the file /apps/api/views/deploy_api.py of the component API Endpoint. The manipulation leads to deserialization. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Source: NVD (National Vulnerability Database)
Vulnerability Type
可信数据的反序列化
Source: NVD (National Vulnerability Database)
Vulnerability Title
OpsManage 代码问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
OpsManage是William.Cao个人开发者的一款代码部署、应用部署、计划任务、设备资产管理平台。 OpsManage存在代码问题漏洞。攻击者利用该漏洞可以导致数据反序列化。以下版本受到影响:3.0.1版本、3.0.2版本、3.0.3版本、3.0.4版本和3.0.5版本。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)
Affected Products
VendorProductAffected VersionsCPESubscribe
welliamcaoOpsManage 3.0.1 -
II. Public POCs for CVE-2024-11662
#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC
III. Intelligence Information for CVE-2024-11662
Please Login to view more intelligence information
IV. Related Vulnerabilities
V. Comments for CVE-2024-11662

No comments yet


Leave a comment