以下是该漏洞描述的中文翻译: 在 yast2-users 中发现了一个操作系统命令注入漏洞。在显示用户“密码设置”选项卡时,位于 中的 函数通过 读取 和 字段。 不进行任何数值验证,并将得到的字符串直接传递给 。该辅助函数将数值通过 Ruby 的反引号(backticks)执行的 shell 命令进行插值,且未对数值进行加引号或转义处理。 影响: 当管理员通过 针对外部/联合 LDAP 目录管理用户时,一旦查看或编辑特定用户的“密码设置”选项卡,就会触发以 root 权限执行命令。无需配置“加入域”或信任关系,仅
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SUSE | yast2-users | 0 ~ 5.0.8 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-59681 | 8.8 HIGH | yast2-auth-client: OS command injection via unsanitized Organizational Unit / dnsHostName |
| CVE-2026-25706 | 7.5 HIGH | yast2-samba-client: OS command injection via attacker-controlled Organizational Unit (Acti |
No comments yet