bytecodealliance Wasmtime是bytecodealliance组织开源的一个WebAssembly与WASI运行时。 bytecodealliance wasmtime存在安全漏洞,该漏洞源于wasmtime-wasi在创建硬链接和重命名时检查目录权限但未匹配源和目标预打开的FilePerms,允许具有只读源文件能力的WASI guest通过wasip1、wasip2或wasip3 filesystem接口覆盖以FilePerms::READ暴露的主机文件。以下版本受到影响:24.0
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| bytecodealliance | wasmtime | < 24.0.11 |
affected |
>= 25.0.0, < 36.0.12 |
affected | ||
>= 37.0.0, < 45.0.3 |
affected | ||
>= 46.0.0, < 46.0.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| bytecodealliance | wasmtime | < 24.0.11 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet