Trivy 在 0.71.0 版本之前存在目录遍历漏洞,该漏洞出现在 Terraform 文件系统函数尝试访问超出扫描根目录的路径名时。当对不可信输入(例如包含 Terraform 配置的第三方拉取请求)执行配置错误扫描(misconf scanning)时,如果在这些非预期路径名中存在敏感数据,且攻击者能够通过这些路径读取到扫描输出中的敏感数据值,就会引发安全风险。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet