漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
openssl_encrypt before 1.4.0 Sandbox Bypass via pathlib and io
Vulnerability Description
openssl_encrypt versions before 1.4.0 contain a sandbox bypass vulnerability where the plugin sandbox fails to restrict alternative file access methods like pathlib.Path and io.open. Attackers can import pathlib or io modules to read and write arbitrary files, completely bypassing the restricted_open file access controls.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Vulnerability Type
保护机制失效
Vulnerability Title
jahlives openssl_encrypt 处理逻辑错误漏洞
Vulnerability Description
jahlives openssl_encrypt是jahlives个人开发者的一款服务器端数据加密处理工具。 jahlives openssl_encrypt 1.4.0之前版本存在处理逻辑错误漏洞,该漏洞源于插件沙箱未能限制pathlib.Path和io.open等替代文件访问方法,攻击者可导入pathlib或io模块读写任意文件,完全绕过restricted_open文件访问控制。
CVSS Information
N/A
Vulnerability Type
N/A