gala-gopher是一种基于 eBPF 的低开销探针框架。 gala-gopher 1.0.2 版本及之前版本存在安全漏洞,该漏洞源于存在操作系统命令注入问题。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| openEuler | gala-gopher | 0 ~ 1.0.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-24892 | 8.1 HIGH | Unauthorized RCE in migration-tools |
| CVE-2024-24897 | 8.1 HIGH | Remote command execution in A-Tune-Collector |
| CVE-2024-24899 | 7.2 HIGH | Command injection in aops-zeus |
| CVE-2021-33632 | 7.0 HIGH | TOCTOU Race Condition problem in iSulad |
No comments yet