GitAhead 2.7.1 及之前版本中存在操作系统命令注入漏洞,该漏洞位于 src/git/Filter.cpp 文件中。攻击者可以通过在 clean/smudge 过滤器命令中注入构造的文件名,从而在恶意仓库中执行任意命令。具体来说,攻击者可以利用 .gitattributes 文件将文件名设置为包含类似 $(command) 的形式,当用户执行 checkout 或 staging 操作时,系统将调用 bash -c 执行该命令,导致受害者的系统中执行恶意命令。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet