Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Windmill < 1.703.2 Incorrect Default Permissions in nsjail Configuration
Vulnerability Description
Windmill prior to 1.703.2 contains an incorrect default permissions vulnerability in nsjail sandbox configuration files where /etc is bind-mounted without read-write restrictions, allowing authenticated users to write arbitrary entries to /etc/hosts, /etc/resolv.conf, and /etc/ssl/certs/ca-certificates.crt from within script execution sandboxes. Attackers can exploit persistent poisoned entries across all subsequent script executions on the same worker pod to redirect hostnames, intercept DNS queries, perform transparent HTTPS man-in-the-middle attacks, and intercept WM_TOKEN JWTs to gain workspace-admin access to other users' workspaces.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Vulnerability Type
缺省权限不正确
Vulnerability Title
Windmill 安全漏洞
Vulnerability Description
Windmill是Windmill Labs, Inc开源的一个低代码开发平台。 Windmill 1.703.2之前版本存在安全漏洞,该漏洞源于nsjail沙箱配置文件中/etc以无读写限制方式绑定挂载,可能导致认证用户从脚本执行沙箱内写入/etc/hosts、/etc/resolv.conf和/etc/ssl/certs/ca-certificates.crt的任意条目,攻击者可利用持久化投毒条目重定向主机名、拦截DNS查询、执行透明HTTPS中间人攻击,并拦截WM_TOKEN JWT以获取跨租户受害
CVSS Information
N/A
Vulnerability Type
N/A