目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2023-30844— Mutagen 安全漏洞

CVSS 3.0 · Low EPSS 0.74% · P51
获取后续新漏洞提醒登录后订阅

一、 漏洞 CVE-2023-30844 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
Mutagen list and monitor operations do not neutralize control characters in text controlled by remote endpoints
来源: CVE Program / CVE List V5
Vulnerability Description
Mutagen provides real-time file synchronization and flexible network forwarding for developers. Prior to versions 0.16.6 and 0.17.1 in `mutagen` and prior to version 0.17.1 in `mutagen-compose`, Mutagen `list` and `monitor` commands are susceptible to control characters that could be provided by remote endpoints. This could cause terminal corruption, either intentional or unintentional, if these characters were present in error messages or file paths/names. This could be used as an attack vector if synchronizing with an untrusted remote endpoint, synchronizing files not under control of the user, or forwarding to/from an untrusted remote endpoint. On very old systems with terminals susceptible to issues such as CVE-2003-0069, the issue could theoretically cause code execution. The problem has been patched in Mutagen v0.16.6 and v0.17.1. Earlier versions of Mutagen are no longer supported and will not be patched. Versions of Mutagen after v0.18.0 will also have the patch merged. As a workaround, avoiding synchronization of untrusted files or interaction with untrusted remote endpoints should mitigate any risk.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:L/A:N
来源: CVE Program / CVE List V5
Vulnerability Type
转义、元或控制序列转义处理不恰当
来源: CVE Program / CVE List V5
Vulnerability Title
Mutagen 安全漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
Mutagen是一种新型的远程开发工具,它使您现有的本地工具能够在远程环境(如云服务器和容器)中使用代码。 Mutagen 0.16.6之前版本 、0.17.1 之前版本和mutagen-compose 0.17.1 之前版本存在安全漏洞,该漏洞源于Mutagen list 和 monitor 命令容易受到远程端点提供的控制字符的影响,可能导致终端损坏。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商产品影响版本CPE订阅
mutagen-iomutagen github.com/mutagen-io/mutagen < 0.16.6 -

二、漏洞 CVE-2023-30844 的公开POC

#POC 描述源链接神龙链接
AI 生成 POC高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2023-30844 的情报信息

登录查看更多情报信息。

CVE-2023-30844 厂商安全公告 (1)

CVE-2023-30844 其他参考 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2023-30844

暂无评论


发表评论