漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Untrusted user data can lead to privilege escalation
Vulnerability Description
Chef InSpec versions up to 5.23 and before 7.0.107 creates named pipes with overly permissive default Windows access controls. A local attacker may interfere with the pipe connection process and exploit the insufficient access restrictions to assume the InSpec execution context, potentially resulting in elevated privileges or operational disruption. This issue affects Chef Inspec: through 5.23 and before 7.0.107
CVSS Information
N/A
Vulnerability Type
特权管理不恰当
Vulnerability Title
Chef InSpec 授权问题漏洞
Vulnerability Description
Chef InSpec是Chef公司的一种开源的自动化测试和合规性检查框架,旨在帮助开发人员和运维团队编写、运行和维护自动化的测试脚本,以验证应用程序和基础设施的合规性和安全性。 Chef InSpec 5.23及之前版本存在授权问题漏洞,该漏洞源于命名管道访问控制过于宽松,可能导致权限提升或操作中断。
CVSS Information
N/A
Vulnerability Type
N/A