漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
nearai ironclaw write_file path_utils.rs validate_path link following
Vulnerability Description
A vulnerability was identified in nearai ironclaw up to 0.29.1. The affected element is the function validate_path of the file src/tools/builtin/path_utils.rs of the component write_file. The manipulation leads to link following. Local access is required to approach this attack. The exploit is publicly available and might be used. The identifier of the patch is 369ff3d240cf3c0787b50e1e9f182e1a06c71255. It is recommended to apply a patch to fix this issue.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Vulnerability Type
在文件访问前对链接解析不恰当(链接跟随)
Vulnerability Title
NEAR AI IronClaw 后置链接漏洞
Vulnerability Description
NEAR AI IronClaw是美国NEAR AI公司的一款服务器系统软件。 NEAR AI IronClaw 0.29.0版本和0.29.1版本存在后置链接漏洞,该漏洞源于write_file组件中src/tools/builtin/path_utils.rs文件的validate_path函数存在链接跟随问题,可能导致本地攻击者利用此漏洞。
CVSS Information
N/A
Vulnerability Type
N/A