Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
OpenChoreo: Authenticated OS command injection via OpenChoreo Workflow Plane templates enables code execution in privileged pods
Vulnerability Description
OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.4, 1.1.4, and 1.2.0-rc.2, OpenChoreo Workflow Plane templates under samples/getting-started/workflow-templates/ interpolated developer-controlled workflow parameters into shell program text executed through sh -c instead of passing the values through container.env, allowing arbitrary commands to run in workflow pods while affected privileged Podman templates lacked hostUsers: false. This issue is fixed in versions 1.0.4, 1.1.4, and 1.2.0-rc.2.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
OS命令中使用的特殊元素转义处理不恰当(OS命令注入)
Vulnerability Title
OpenChoreo 命令注入漏洞
Vulnerability Description
OpenChoreo是openchoreo组织开源的一个面向 Kubernetes 的开发者平台。 OpenChoreo 1.0.4之前版本、1.1.4之前版本和1.2.0-rc.2之前版本存在命令注入漏洞,该漏洞源于将开发者控制的工作流参数插入到通过sh -c执行的shell程序文本中,而非通过container.env传递,可能导致任意命令执行。
CVSS Information
N/A
Vulnerability Type
N/A