漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
GitHub CLI: Unescaped variable components in request URLs could allow path traversal
Vulnerability Description
GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.97.0, some HTTP request URLs interpolate variable path components without percent encoding, allowing URL path metacharacters in attacker-controlled repository or resource values to make gh address a different API endpoint or resource than the user intended. This issue is fixed in version 2.97.0.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Vulnerability Title
GitHub CLI 路径遍历漏洞
Vulnerability Description
GitHub CLI是GitHub CLI组织开源的一款命令行界面工具。 GitHub CLI 2.97.0之前版本存在路径遍历漏洞,该漏洞源于HTTP请求URL在插入可变路径组件时未进行百分号编码,攻击者控制的仓库或资源值中的URL路径元字符可能使gh访问非预期的API端点或资源。
CVSS Information
N/A
Vulnerability Type
N/A