AI Toolkit是美国Splunk公司的一个机器学习工具包 Splunk ai toolkit 5.7.4之前版本存在命令注入漏洞,该漏洞源于btool配置助手中存在不安全的shell执行模式,从动态参数构造OS命令字符串时未禁用shell解释,可能导致持有admin角色的用户在运行Splunk Enterprise实例的主机上执行任意OS命令。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Splunk | Splunk AI Toolkit | 5.7< 5.7.4 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Splunk | Splunk AI Toolkit | 5.7 ~ 5.7.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet