Argo CD 是一个用于 Kubernetes 的声明式 GitOps 持续交付工具。在版本 2.11.0 至 3.3.15、3.4.10、3.5.4 以及 3.6.0-rc2 之间,Argo CD 的 repo-server 存在命令注入漏洞。当配置了代理 URL 的 SSH Git 仓库进行克隆、测试或获取操作时,该漏洞便会被触发。在此过程中,代理主机和端口会被嵌入到通过 Shell 执行的 SSH ProxyCommand 中,但并未对 Shell 元字符进行转义或清理。 攻击者若具备创建或更新仓库或仓库凭
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet