Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Vulnerability in the Oracle Cloud Native Environment Command Line Interface product of Oracle Open Source Projects. The supported versions that is affected is v2.3.2. Easily exploitable vulnerability allows unauthenticated attacker to compromise Oracle Cloud Native Environment Command Line Interface product via a malicious environment variable. Successful attacks of this vulnerability can result in Oracle Cloud Native Environment Command Line Interface allowing users to execute arbitrary code.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
Vulnerability Type
N/A
Vulnerability Title
Oracle Cloud Native Environment Command Line Interface 代码注入漏洞
Vulnerability Description
Oracle Cloud Native Environment Command Line Interface是美国甲骨文(Oracle)公司的一个云原生环境集群管理命令行工具。 Oracle Cloud Native Environment Command Line Interface v2.3.2版本存在代码注入漏洞,该漏洞源于可能导致未经身份验证的攻击者通过恶意环境变量,使用户执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A