CVE-2024-50603
Aviatrix Controllers OS Command Injection Vulnerability
⚠ KEVEPSS 98.5%
描述
Aviatrix Controllers contain an OS command injection vulnerability that could allow an unauthenticated attacker to execute arbitrary code. Shell metacharacters can be sent to /v1/api in cloud_type for list_flightpath_destination_instances, or src_cloud_type for flightpath_connection_test.
如何修補 CVE-2024-50603
OSV 沒有提供套件對應 — 請參考下方連結尋找廠商提供的建議。
CVE-2024-50603 正在被利用嗎?
是 — CVE-2024-50603 已列入 CISA Known Exploited Vulnerabilities (KEV) 清單,代表正在被實際利用,請立即修補。
受影響套件(0)
OSV 沒有提供套件對應。