受影响的 Puppet Enterprise 版本中,在 参数的处理过程中存在一个命令注入漏洞。拥有 Puppet 管理员权限的认证用户通过为该参数提供特制值,可以向一个缺乏充分净化的 shell 执行上下文中注入任意 shell 命令。由于生成的命令以 root 权限执行,成功利用该漏洞可能导致受影响系统的完全失陷。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Perforce Software | Puppet Enterprise | 2023.8.4 ~ 2023.8.10 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet