Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Brave UX for-the-badge combine-prs.yml os command injection
Vulnerability Description
A vulnerability was found in Brave UX for-the-badge and classified as critical. Affected by this issue is some unknown functionality of the file .github/workflows/combine-prs.yml. The manipulation leads to os command injection. The name of the patch is 55b5a234c0fab935df5fb08365bc8fe9c37cf46b. It is recommended to apply a patch to fix this issue. VDB-216842 is the identifier assigned to this vulnerability.
CVSS Information
CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
Vulnerability Type
OS命令中使用的特殊元素转义处理不恰当(OS命令注入)
Vulnerability Title
Brave 操作系统命令注入漏洞
Vulnerability Description
Brave是美国Brave公司的一个快速,私密和安全的Web浏览器。 Brave UX for-the-badge存在操作系统命令注入漏洞,该漏洞源于其.github/workflows/combine-prs.yml文件中的若干未知函数允许攻击者实现系统命令注入。
CVSS Information
N/A
Vulnerability Type
N/A