漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Rapid7 Velociraptor Directory Traversal Vulnerability
Vulnerability Description
Rapid7 Velociraptor versions before 0.75.6 contain a directory traversal issue on Linux servers that allows a rogue client to upload a file which is written outside the datastore directory. Velociraptor is normally only allowed to write in the datastore directory. The issue occurs due to insufficient sanitization of directory names which end with a ".", only encoding the final "." AS "%2E". Although files can be written to incorrect locations, the containing directory must end with "%2E". This limits the impact of this vulnerability, and prevents it from overwriting critical files.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Vulnerability Title
Rapid7 Velociraptor 安全漏洞
Vulnerability Description
Rapid7 Velociraptor是美国Rapid7公司的一个数字取证与事件响应平台。 Rapid7 Velociraptor 0.75.6之前版本存在安全漏洞,该漏洞源于Linux服务器上目录名清理不足,可能导致目录遍历和文件写入错误位置。
CVSS Information
N/A
Vulnerability Type
N/A