漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
DbGate: Remote Code Execution via functionName injection in loadReader endpoint
Vulnerability Description
DbGate is cross-platform database manager. In versions 7.1.8 and prior, the POST /runners/load-reader endpoint in DbGate accepts a functionName parameter that is directly interpolated into a JavaScript code template without any sanitization or validation. An authenticated user (with basic access, no special permissions required) can inject arbitrary JavaScript code that executes on the server with full process privileges, bypassing the require=null sandbox restriction. An authenticated user with basic access (no admin role, no run-shell-script permission required) can: execute arbitrary OS commands on the DbGate server with the privileges of the Node.js process, read/write any file accessible to the process, pivot to connected databases by reading connection credentials from DbGate's storage, and compromise the host system - in Docker deployments, this typically means root access within the container. Version 7.1.9 contains a patch.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
对生成代码的控制不恰当(代码注入)
Vulnerability Title
DbGate 代码注入漏洞
Vulnerability Description
DbGate是DbGate个人开发者开源的一个数据库管理器。 DbGate 7.1.8及之前版本存在代码注入漏洞,该漏洞源于POST /runners/load-reader端点中的functionName参数被直接插入JavaScript代码模板且未经清理或验证,可能导致经过身份验证的用户注入任意JavaScript代码,以完整进程权限执行,绕过require=null沙箱限制。
CVSS Information
N/A
Vulnerability Type
N/A