-
Notifications
You must be signed in to change notification settings - Fork 1.7k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
修复插件shell命令注入漏洞 #1316
修复插件shell命令注入漏洞 #1316
Conversation
修复插件shell命令注入漏洞
Codecov Report
@@ Coverage Diff @@
## master #1316 +/- ##
=======================================
Coverage 78.01% 78.01%
=======================================
Files 78 78
Lines 12220 12220
=======================================
Hits 9534 9534
Misses 2686 2686
Continue to review full report at Codecov.
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM
修复插件shell命令注入漏洞 - 通过实例信息注入
和上个pr的冲突需要解决一下 |
已处理 |
相关issue:后端RCE
之前参数注入漏洞已经修复过,但是用同样的方法可以通过配置各个插件的path或实例信息来注入自定义命令
补充:
2. 或在实例信息中注入:
影响范围:
soar
binglog2sql
sqladvisor
binlog
instance
修复:
与参数一样使用shlex.quote处理path