DevSpace 6.3.21 及更早版本未能拒绝来自 Pod 内同步流的 tar 条目名称中的父目录段。攻击者若操控恶意容器,可以通过流式传输包含遍历序列的 tar 条目,从而在开发者工作站上写入任意文件,进而实现代码执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet