黑盾(Black Duck)blackduck-c-cpp 1.0.17 至 3.0.6 版本中,由于在进程中使用了可见的敏感信息,存在安全隐患。攻击者若能在被扫描项目的构建环境中执行代码,即可通过子进程继承的环境变量获取 Black Duck API 令牌。这些子进程是在构建捕获和签名扫描期间启动的。此问题仅在通过 或 环境变量提供令牌时适用。 升级并不能补救已泄露的令牌;因此,对于受影响的版本,通过环境变量提供的所有令牌都应重新生成(轮换)。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Black Duck | blackduck-c-cpp | 1.0.17 ~ 3.0.7 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet