漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Remote Code Execution (RCE) via Server Side Template Injection (SSTI) in Airbyte
Vulnerability Description
Airbyte is a data integration platform for ELT pipelines. Airbyte connection builder docker image is vulnerable to RCE via SSTI which allows an authenticated remote attacker to execute arbitrary code on the server as the web server user. The connection builder is used to create and test new connectors. Sensitive information, such as credentials, could be exposed if a user tested a new connector on a compromised instance. The connection builder does not have access to any data processes. This vulnerability is fixed in 0.62.2.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Vulnerability Type
CWE-1336
Vulnerability Title
Airbyte 安全漏洞
Vulnerability Description
Airbyte是Airbyte开源的一个 ETL/ELT 数据管道数据集成平台。 Airbyte v0.62.2之前版本存在安全漏洞,该漏洞源于存在远程代码执行漏洞,允许经过身份验证的远程攻击者以Web服务器用户的身份在服务器上执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A