在 Chainguard Academy (edu) 的 integrate-platform-docs 复合 GitHub Action 中,存在一处操作系统命令中特殊元素处理不当的安全漏洞。该漏洞存在于提交哈希 7375a80caabcc31c33ec90f29687ed78c13d16ff 至 fb0efb2537d326ab18c07d620875b8ed2a4b39f3 之间的版本。 攻击者若能控制 或 输入参数,即可在 GitHub Actions 运行器上执行任意 Shell 命令。原因是这些输入参数
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Chainguard | Chainguard Academy (edu) | 7375a80caabcc31c33ec90f29687ed78c13d16ff ~ fb0efb2537d326ab18c07d620875b8ed2a4b39f3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet