漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Packer vulnerable to arbitrary file write via crafted plugin archive during installation
Vulnerability Description
Packer up to 1.15.4 is vulnerable to an issue in the third-party plugin installer that may allow unintended file system modification and could lead to code execution. A user who installs a plugin from a malicious or compromised source may be affected. This vulnerability (CVE-2026-19589) is fixed in Packer 1.16.0.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:N
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Vulnerability Title
HashiCorp Packer 路径遍历漏洞
Vulnerability Description
HashiCorp Packer是美国HashiCorp公司开源的一个自动化镜像构建工具。 HashiCorp Packer存在路径遍历漏洞,该漏洞源于第三方插件安装程序问题,可能导致非预期的文件系统修改和代码执行。
CVSS Information
N/A
Vulnerability Type
N/A