以下是对该漏洞描述的中文翻译: PowSyBl(Power System Blocks) 是一个用于构建面向电力系统的软件框架。在 7.2.2 版本之前, 和 在通过 或 执行命令时,将命令参数和环境变量直接拼接为字符串,且未进行充分的转义处理。 如果攻击者控制的值传递至 、 、 、 、 或 / ,攻击者可能突破原本预期的命令执行范围,以 JVM 用户的身份执行任意 Shell 命令。 受影响的 itools 路径包括:带有 参数的 action-simulator、带有 参数的 security-analysis
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| powsybl | powsybl-core | < 7.2.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| powsybl | powsybl-core | < 7.2.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet