Hydra 是一个用于优雅配置复杂应用程序的框架。在版本 1.3.4 之前, 方法通过 中的 函数解析并调用由配置文件选定的 Python 对象。这使得攻击者能够利用其控制的 target 值及参数来选择并执行危险的 callable 对象。 因此,任何将不受信任的配置文件、命令行(CLI)覆盖参数或模型元数据传入 的应用程序、库、CLI 工作流或模型加载器,都可能在其自身进程中执行任意代码,包括读取或修改文件与凭据,甚至终止进程。 从版本 1.3.4 开始,引入了目标(target)拦截机制,并提供了一个显式的
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| facebookresearch | hydra | < 1.3.4 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| facebookresearch | hydra | < 1.3.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No comments yet