yast2-auth-client 中存在一个操作系统命令注入漏洞。能够控制活动目录(Active Directory)配置值的攻击者可以利用该漏洞,在目标主机上以 root 权限执行任意命令。 具体来说,位于 中的 模块在组装 、 和 命令时,通过将配置值直接插入到一个命令字符串中,并将该字符串传递给 / 执行。这会导致 Ruby 通过 来运行该命令。由于组织单元(OU)、DNS 主机名(dnshostname)、活动目录用户名(AD user name)和活动目录域名(AD domain name)这些值既未经
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SUSE | yast2-auth-client | 0 ~ 5.0.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-59680 | 8.0 HIGH | yast2-users: OS command injection via LDAP-supplied shadowLastChange/shadowExpire attribut |
| CVE-2026-25706 | 7.5 HIGH | yast2-samba-client: OS command injection via attacker-controlled Organizational Unit (Acti |
No comments yet