CVE编号
CVE-2022-24803利用情况
暂无补丁情况
N/A披露时间
2022-04-01漏洞描述
Asciidoctor-include-ext is Asciidoctor’s standard include processor reimplemented as an extension. Versions prior to 0.4.0, when used to render user-supplied input in AsciiDoc markup, may allow an attacker to execute arbitrary system commands on the host operating system. This attack is possible even when `allow-uri-read` is disabled! The problem has been patched in the referenced commits.解决建议
建议您更新当前系统或软件至最新版,完成漏洞的修复。
参考链接 |
|
---|---|
https://github.com/jirutka/asciidoctor-include-ext/commit/c7ea001a597c7033575... | |
https://github.com/jirutka/asciidoctor-include-ext/commit/cbaccf3de533cbca224... | |
https://github.com/jirutka/asciidoctor-include-ext/security/advisories/GHSA-v... |
受影响软件情况
# | 类型 | 厂商 | 产品 | 版本 | 影响面 | ||||
1 | |||||||||
---|---|---|---|---|---|---|---|---|---|
运行在以下环境 | |||||||||
应用 | asciidoctor-include-ext_project | asciidoctor-include-ext | * |
Up to (excluding) 0.4.0 |
|||||
运行在以下环境 | |||||||||
系统 | debian_11 | ruby-asciidoctor-include-ext | * |
Up to (excluding) 0.3.1-2 |
|||||
运行在以下环境 | |||||||||
系统 | debian_12 | ruby-asciidoctor-include-ext | * |
Up to (excluding) 0.3.1-2 |
|||||
运行在以下环境 | |||||||||
系统 | debian_sid | ruby-asciidoctor-include-ext | * |
Up to (excluding) 0.3.1-2 |
- 攻击路径 网络
- 攻击复杂度 低
- 权限要求 无
- 影响范围 未更改
- 用户交互 无
- 可用性 高
- 保密性 高
- 完整性 高
还没有评论,来说两句吧...