oscal-compass compliance-trestle是oscal-compass组织的一个合规管理工具。 oscal-compass compliance-trestle 3.12.2之前版本和4.0.3之前版本存在安全漏洞,该漏洞源于对 命令的 参数中的 、 或绝对路径验证不当,可能允许攻击者在预期工作区之外写入任意文件。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| oscal-compass | compliance-trestle | >= 4.0.0, < 4.0.3 |
affected |
< 3.12.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| oscal-compass | compliance-trestle | >= 4.0.0, < 4.0.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No comments yet