@oblique Oblique是@oblique组织的一款集威胁情报分析与网络防护于一体的安全产品。 @oblique Oblique 15.4.0版本存在命令注入漏洞,该漏洞源于通过字符串连接构造shell命令,未正确中和用户控制的project-name参数,可能导致执行额外的操作系统命令。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Swiss Federal Office of Information Technology, Systems and Telecommunication | @oblique/cli | 15.4.0< 15.4.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Swiss Federal Office of Information Technology, Systems and Telecommunication | @oblique/cli | 15.4.0 ~ 15.4.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No comments yet