Black Duck blackduck-c-cpp 3.0.7 之前版本中的包管理器组件存在操作系统命令特殊元素未正确中和的漏洞。该漏洞允许攻击者在扫描构建目录内创建文件后,以执行扫描的账户身份执行操作系统命令。 在遍历扫描目录时遇到的文件系统路径会被插值到通过 shell 执行的命令字符串中,且未进行引号包裹或转义处理,因此这些路径中的 shell 元字符会被解释为命令执行的一部分,而非作为纯文本处理。此漏洞无需对构建命令或工具配置拥有任何控制权即可被利用。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Black Duck | blackduck-c-cpp | < 3.0.7 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Black Duck | blackduck-c-cpp | 0 ~ 3.0.7 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet