目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

CVE-2024-3322— LoLLMs 路径遍历漏洞

AI Predicted 9.8 Difficulty: Easy EPSS 0.73% · P51
新しい脆弱性情報の通知を購読するログインして購読

I. CVE-2024-3322の基本情報

脆弱性情報

脆弱性についてご質問がありますか?Shenlongの分析が参考になるかご確認ください!
Shenlongの10の質問を表示 ↗

高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。

脆弱性タイトル
Path Traversal in parisneo/lollms-webui
ソース: CVE Program / CVE List V5
脆弱性説明
A path traversal vulnerability exists in the 'cyber_security/codeguard' native personality of the parisneo/lollms-webui, affecting versions up to 9.5. The vulnerability arises from the improper limitation of a pathname to a restricted directory in the 'process_folder' function within 'lollms-webui/zoos/personalities_zoo/cyber_security/codeguard/scripts/processor.py'. Specifically, the function fails to properly sanitize user-supplied input for the 'code_folder_path', allowing an attacker to specify arbitrary paths using '../' or absolute paths. This flaw leads to arbitrary file read and overwrite capabilities in specified directories without limitations, posing a significant risk of sensitive information disclosure and unauthorized file manipulation.
ソース: CVE Program / CVE List V5
CVSS情報
N/A
ソース: CVE Program / CVE List V5
脆弱性タイプ
对路径名的限制不恰当(路径遍历)
ソース: CVE Program / CVE List V5
脆弱性タイトル
LoLLMs 路径遍历漏洞
ソース: CNNVD (China National Vulnerability Database)
脆弱性説明
LoLLMs是Saifeddine ALOUI个人开发者的一个大型语言多模式系统的 Web UI。 LoLLMs 存在路径遍历漏洞,该漏洞源于应用程序中存在路径遍历漏洞。
ソース: CNNVD (China National Vulnerability Database)
CVSS情報
N/A
ソース: CNNVD (China National Vulnerability Database)
脆弱性タイプ
N/A
ソース: CNNVD (China National Vulnerability Database)

影響を受ける製品

ベンダープロダクト影響を受けるバージョンCPE購読
parisneoparisneo/lollms-webui unspecified ~ 9.5 -

II. CVE-2024-3322の公開POC

#POC説明ソースリンクShenlongリンク
AI生成POCプレミアム

公開POCは見つかりませんでした。

ログインしてAI POCを生成

III. CVE-2024-3322のインテリジェンス情報

登录查看更多情报信息。

CVE-2024-3322 补丁与修复 (1)

CVE-2024-3322 厂商安全公告 (1)

Same Patch Batch · parisneo · 2024-06-06 · 12 CVEs total

CVE-2024-1873Path Traversal and Denial of Service in parisneo/lollms-webui
CVE-2024-5482SSRF in add_webpage endpoint in parisneo/lollms-webui
CVE-2024-2624Path Traversal and Arbitrary File Upload Vulnerability in parisneo/lollms-webui
CVE-2024-2362Path Traversal in parisneo/lollms-webui
CVE-2024-2360Path Traversal leading to Remote Code Execution in parisneo/lollms-webui
CVE-2024-2359Improper Neutralization of Special Elements used in an OS Command in parisneo/lollms-webui
CVE-2024-2548Path Traversal in parisneo/lollms-webui
CVE-2024-2288CSRF File Upload Vulnerability in parisneo/lollms-webui
CVE-2024-3429Path Traversal in parisneo/lollms
CVE-2024-4881Path Traversal in parisneo/lollms
CVE-2024-4320Remote Code Execution due to LFI in '/install_extension' in parisneo/lollms-webui

IV. 関連脆弱性

V. CVE-2024-3322へのコメント

まだコメントはありません


コメントを残す