Dool 在 1.3.8 及更早版本中,当使用 “--devel” 标志时,易受符号链接跟随(symlink following)漏洞影响。原因是应用程序在打开日志文件时未使用 标志。本地攻击者可以通过在预期的日志文件路径创建一个指向敏感文件的符号链接来利用此漏洞,导致 dool 将日志数据截断并覆盖目标文件。如果 dool 以较高权限(如 root)运行,其影响尤为严重。 该问题已通过拉取请求 #116 得到修复。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| scottchiefbaker | dool | ≤ 1.3.8 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| scottchiefbaker | dool | 0 ~ 1.3.8 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet