漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
bentoml OpenLLM Model Repository Directory Name common.py async_run_command command injection
Vulnerability Description
A vulnerability was found in bentoml OpenLLM 0.6.30. This affects the function async_run_command of the file src/openllm/common.py of the component Model Repository Directory Name Handler. Performing a manipulation of the argument cmd results in command injection. Attacking locally is a requirement. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Vulnerability Type
在命令中使用的特殊元素转义处理不恰当(命令注入)
Vulnerability Title
BentoML OpenLLM 输入验证错误漏洞
Vulnerability Description
BentoML OpenLLM是BentoML公司开源的一个开源 LLM。 BentoML OpenLLM 0.6.30版本存在安全漏洞,该漏洞源于Model Repository Directory Name Handler组件中文件src/openllm/common.py的函数async_run_command对参数cmd的操作,可能导致命令注入。
CVSS Information
N/A
Vulnerability Type
N/A