漏洞描述
The Square Squash allows remote attackers to execute arbitrary code via a YAML document in the (1) namespace parameter to the deobfuscation function or (2) sourcemap parameter to the sourcemap function in app/controllers/api/v1_controller.rb.
影响产品
暂无结构化产品信息。
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
exchange.xforce.ibmcloud.comhttps://exchange.xforce.ibmcloud.com/vulnerabilities/86335↗ceriksen.comhttp://ceriksen.com/2013/08/06/squash-remote-code-execution-vulnerability-advisory/↗osvdb.orghttp://osvdb.org/95992↗github.comhttps://github.com/SquareSquash/web/commit/6d667c19e96e4f23dccbfbe24afeebd18e98e1c5↗