漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
漏洞
Lightning Flow Scanner is Vulnerable to Code Injection via Unsafe Use of new Function() in APIVersion Rule
漏洞信息
Lightning Flow Scanner provides a A CLI plugin, VS Code Extension and GitHub Action for analysis and optimization of Salesforce Flows. Versions 6.10.5 and below allow a maliciously crafted flow metadata file to cause arbitrary JavaScript execution during scanning. The APIVersion rule uses new Function() to evaluate expression strings, enabling an attacker to supply a malicious expression within rule configuration or crafted flow metadata. This could compromise developer machines, CI runners, or editor environments. This issue is fixed in version 6.10.6.
漏洞信息
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
漏洞
对生成代码的控制不恰当(代码注入)
漏洞
lightning-flow-scanner 代码注入漏洞
漏洞信息
lightning-flow-scanner是Lightning Flow Scanner开源的一个命令行自动化插件。 lightning-flow-scanner 6.10.5及之前版本存在代码注入漏洞,该漏洞源于恶意构造的流元数据文件可能导致任意JavaScript执行。
漏洞信息
N/A
漏洞
N/A