漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Cockpit CMS 2.14.0 Authenticated Command Injection via FFmpeg Filename
Vulnerability Description
Cockpit CMS 2.14.0 and prior contains a command injection vulnerability in the FFmpeg integration that allows authenticated users with only the assets/upload permission to execute arbitrary commands by uploading a video file with a shell metacharacter-laden filename. The unsanitized filename is interpolated into a shell command executed via Process::fromShellCommandline() before the slugify() sanitizer runs, enabling injected shell metacharacters such as backticks, $(), and semicolons to escape the FFmpeg command context and execute as the web-server user.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
OS命令中使用的特殊元素转义处理不恰当(OS命令注入)
Vulnerability Title
Cockpit CMS 命令注入漏洞
Vulnerability Description
Cockpit CMS是Cockpit组织的一款内容管理系统。 Cockpit CMS 2.14.0及之前版本存在命令注入漏洞,该漏洞源于FFmpeg集成中未充分清理上传文件名,导致命令注入,可能允许仅具有assets/upload权限的认证用户通过上传包含shell元字符的视频文件执行任意命令。
CVSS Information
N/A
Vulnerability Type
N/A