漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Zip Slip Arbitrary File Write in AWS diagram-as-code (awsdac)
Vulnerability Description
A relative path traversal issue in the zip extraction functionality in AWS diagram-as-code (awsdac) in versions 0.10 through 0.23 can allow a third party to write arbitrary files to the local filesystem via crafted zip entry names containing path traversal sequences. This could allow the third party to perform inappropriate actions in the diagram bundle.
To remediate this issue, users should upgrade to the version 0.24 or later.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
Vulnerability Type
相对路径遍历
Vulnerability Title
Amazon Diagram-as-code 路径遍历漏洞
Vulnerability Description
Amazon Diagram-as-code是美国Amazon公司的一款通过代码形式创建图表的软件。 Amazon Diagram-as-code 0.10版本至0.23版本存在路径遍历漏洞,该漏洞源于zip解压功能存在相对路径遍历问题,可能导致第三方通过包含路径遍历序列的特制zip条目名称向本地文件系统写入任意文件。
CVSS Information
N/A
Vulnerability Type
N/A