漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Lupa has a Sandbox escape and RCE due to incomplete attribute_filter enforcement in getattr / setattr
Vulnerability Description
Lupa integrates the runtimes of Lua or LuaJIT2 into CPython. In 2.6 and earlier, attribute_filter is not consistently applied when attributes are accessed through built-in functions like getattr and setattr. This allows an attacker to bypass the intended restrictions and eventually achieve arbitrary code execution.
CVSS Information
N/A
Vulnerability Type
访问控制不恰当
Vulnerability Title
Lupa 安全漏洞
Vulnerability Description
Lupa是scoder个人开发者的一个将Lua运行时嵌入Python的桥接库。 Lupa 2.6及之前版本存在安全漏洞,该漏洞源于属性过滤器未在getattr和setattr等内置函数中一致应用,可能导致绕过限制并执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A