Polyaxon 2.16.4 及更早版本在服务器端运行准备阶段,使用未沙箱化的 Jinja2 环境渲染操作规范(operation specification)字段,这使得经过身份验证的用户能够执行任意代码。攻击者可以在队列(queue)、命名空间(namespace)、条件(conditions)、预设(presets)或依赖项(dependencies)字段中提交包含 Jinja2 有效载荷的运行请求,从而在调度器(scheduler)进程的上下文中执行操作系统命令,导致数据库凭据和服务令牌泄露。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet