Ground Station 是一款基于浏览器的卫星跟踪、软件无线电(SDR)接收、硬件控制以及遥测解码软件套件。在版本 0.4.13 之前,存在以下安全漏洞: 1. 未经认证的远程路径遍历与任意文件写入漏洞 未经身份验证的 Socket.IO 命令会将攻击者控制的 参数从 传递至 。在此处, 函数允许使用绝对路径或父目录遍历(如 ),从而导致攻击者能够将经过 base64 解码后的字节内容写入到 目录之外的任意位置。 2. 日志配置反序列化远程代码执行(RCE)漏洞 攻击者可利用上述任意文件写入漏洞,在目标系统中
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| sgoudelis | ground-station | < 0.4.13 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| sgoudelis | ground-station | < 0.4.13 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No comments yet