漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Trivy: Path traversal via a crafted vulnerability database or other downloaded artifacts
Vulnerability Description
Trivy is a security scanner. Prior to 0.71.1, when Trivy downloads an OCI artifact, it uses the org.opencontainers.image.title annotation from the artifact manifest as the destination filename without validation. An attacker who can make Trivy fetch an attacker-controlled artifact can supply a crafted annotation that resolves to a path outside the intended destination, causing Trivy to write the layer content to an arbitrary location on the host filesystem. This vulnerability is fixed in 0.71.1.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Vulnerability Title
Aqua Security Trivy 路径遍历漏洞
Vulnerability Description
Aqua Security Trivy是Aqua Security公司开源的一款全面且多功能的安全扫描仪。 Aqua Security Trivy 0.71.1之前版本存在路径遍历漏洞,该漏洞源于在下载OCI工件时未对org.opencontainers.image.title注释进行验证,可能导致攻击者通过特制注释将层内容写入主机文件系统的任意位置。
CVSS Information
N/A
Vulnerability Type
N/A