Eclipse aeriOS Self-orchestrator 在 1.2.1 版本之前存在 REST API 中的路径遍历漏洞。用于创建、更新或删除 Self-orchestrator 资源的用户可控标识符在未进行充分验证或过滤的情况下被直接拼接到文件系统路径中。因此,能够访问 Self-orchestrator API 的未认证远程攻击者可以提交包含路径遍历序列的精心构造的标识符,从而在预期应用目录之外写入或删除 JSON 文件(受 Self-orchestrator 进程的文件系统权限限制)。 由于受影响的
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Eclipse Foundation | Eclipse aeriOS | 63993c83fb71bb2c4981731b4980ff93c72a6750< c42da0014069528d149ff9f8b038ac93c38a766c |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Eclipse Foundation | Eclipse aeriOS | 63993c83fb71bb2c4981731b4980ff93c72a6750 ~ c42da0014069528d149ff9f8b038ac93c38a766c | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82180 | 9.5 CRITICAL | CVE-2026-82180 |
| CVE-2026-80515 | 8.9 HIGH | Eclipse Arrowhead 5.0.0-5.2.1 认证授权绕过 |
| CVE-2026-84736 | 8.3 HIGH | Eclipse aeriOS Federator默认禁用TLS证书校验漏洞 |
No comments yet