是一个用于容器工具的通用安装程序和更新器。在 0.27.6 版本之前, 中的 命令会使用 解析环境变量 或 ,并将每个以空格分隔的后缀作为参数传递给所选编辑器可执行文件。能够影响编辑器环境变量并触发 hook 编辑的攻击者,可以提供意外的编辑器参数,从而以 进程账户的特权执行非预期操作。注意:Go 的 不会对这些参数中的 shell 操作符进行求值,因此该安全公告中的 wrapper 演示仅证明了参数传递,并未证明 shell 命令解释。此问题已在 0.27.6 版本中修复。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| uniget-org | cli | < 0.27.6 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| uniget-org | cli | < 0.27.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet