漏洞描述
Code Injection in GitHub repository pyload/pyload prior to 0.5.0b3.dev31.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
huntr.devhttps://huntr.dev/bounties/3fd606f7-83e1-4265-b083-2e1889a05e65/↗nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2022-1058↗packetstormsecurity.comhttp://packetstormsecurity.com/files/171096/pyLoad-js2py-Python-Execution.html↗packetstormsecurity.comhttp://packetstormsecurity.com/files/172914/PyLoad-0.5.0-Remote-Code-Execution.html↗