CWE-76
Improper Neutralization of Equivalent Special Elements
Produkt prawidłowo neutralizuje określone elementy specjalne, ale nieprawidłowo neutralizuje równoważne elementy specjalne. To może prowadzić do obejścia mechanizmów bezpieczeństwa lub wykonania niezamierzonego kodu.
The product correctly neutralizes certain special elements, but it improperly neutralizes equivalent special elements.
Biblioteka `simple-git` (wersje 3.15.0–3.22.x oraz 3.23.1–3.32.2) zawiera podatność umożliwiającą zdalne wykonanie kodu (RCE) poprzez command injection. Podatność pozwala atakującemu ominąć poprawki wprowadzone dla dwóch wcześniejszych podatności (CVE-2022-25860 i CVE-2022-25912) i przejąć pełną kontrolę nad maszyną hosta.
BerriAI LiteLLM zawiera podatność Server-Side Template Injection (SSTI) w endpoincie `/completions`, pozwalającą nieuwierzytelnionemu atakującemu na zdalne wykonanie kodu na serwerze. Podatność posiada krytyczny wynik CVSS 9.8, co czyni ją zagrożeniem najwyższego priorytetu.
Biblioteka llama-cpp-python zawiera podatność klasy Server Side Template Injection (SSTI) w mechanizmie przetwarzania szablonów czatu Jinja2, która umożliwia wykonanie dowolnego kodu na serwerze (RCE). Wynika to z braku piaskownicy (sandbox) podczas renderowania szablonów pobieranych z metadanych plików modeli .gguf.
When NGINX Ingress Controller is configured with Ingress annotations, an injection vulnerability exists in the configuration generator of NGINX Ingress Controller. Multiple user-controllable fields are written into the generated NGINX configuration without sanitization. An authenticated attacker with permission to create or modify these annotations may craft values that inject arbitrary NGINX configuration directives. Impact: An authenticated attacker granted write access to NGINX Ingress Controller Ingress annotations through the Kubernetes API may be able to inject arbitrary NGINX configuration directives, create or delete files, or disable services. There is no data plane exposure; this is a control plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Biblioteka DSSRF dla Node.js, przeznaczona do ochrony przed atakami SSRF, zawiera lukę umożliwiającą obejście mechanizmu walidacji wewnętrznych adresów IP. Atakujący może spreparować URL, który przejdzie weryfikację bezpieczeństwa i skieruje żądanie do wewnętrznej infrastruktury sieciowej.
W NGINX Ingress Controller istnieje podatność typu injection w generatorze konfiguracji, aktywna gdy kontroler skonfigurowany jest z użyciem Custom Resource Definitions (CRDs) lub adnotacji Ingress. Uwierzytelniony atakujący z uprawnieniami do zapisu może wstrzyknąć dowolne dyrektywy konfiguracyjne NGINX, co może prowadzić do poważnych skutków w warstwie sterowania klastrem Kubernetes.
Description: When NGINX Plus is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NGINX configuration generator component of NGINX Gateway Fabric. User-supplied string values from the Authentication Filter Custom Resource Definition clientID or cookieName fields, or in the clientSecret field of a Secret referenced by an Authentication Filter, are rendered directly into NGINX configuration templates without sanitization or escaping. Impact: An authenticated attacker with permission to create or modify these resources may craft values that inject arbitrary NGINX configuration directives. This is a control plane issue; there is no data plane exposure.
When NGINX Plus is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NGINX configuration generator component of NGINX Gateway Fabric. User-supplied string values from the NginxProxy Custom Resource Definition serverTokens field and the AuthenticationFilter Custom Resource Definition extraAuthArgs field are rendered directly into NGINX configuration templates without sanitization or escaping. An authenticated attacker with permission to create or modify these Custom Resource Definitions may craft values that inject arbitrary NGINX configuration directives. This is a control plane issue; there is no data plane exposure from the vulnerability trigger itself. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
parisneo/lollms-webui, in its latest version, is vulnerable to remote code execution due to an insecure dependency on llama-cpp-python version llama_cpp_python-0.2.61+cpuavx2-cp311-cp311-manylinux_2_31_x86_64. The vulnerability arises from the application's 'binding_zoo' feature, which allows attackers to upload and interact with a malicious model file hosted on hugging-face, leading to remote code execution. The issue is linked to a known vulnerability in llama-cpp-python, CVE-2024-34359, which has not been patched in lollms-webui as of commit b454f40a. The vulnerability is exploitable through the application's handling of model files in the 'bindings_zoo' feature, specifically when processing gguf format model files.
This vulnerability allows an already authenticated admin user to create a malicious payload that could be leveraged for remote code execution on the server hosting the PaperCut NG/MF application server.
An Improper Neutralization of Equivalent Special Elements vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on PTX Series allows a unauthenticated, adjacent attacker to cause a Denial of Service (DoS). When MPLS packets are meant to be sent to a flexible tunnel interface (FTI) and if the FTI tunnel is down, these will hit the reject NH, due to which the packets get sent to the CPU and cause a host path wedge condition. This will cause the FPC to hang and requires a manual restart to recover. Please note that this issue specifically affects PTX1000, PTX3000, PTX5000 with FPC3, PTX10002-60C, and PTX10008/16 with LC110x. Other PTX Series devices and Line Cards (LC) are not affected. The following log message can be seen when the issue occurs: Cmerror Op Set: Host Loopback: HOST LOOPBACK WEDGE DETECTED IN PATH ID <id> (URI: /fpc/<fpc>/pfe/<pfe>/cm/<cm>/Host_Loopback/<cm>/HOST_LOOPBACK_MAKE_CMERROR_ID[<id>]) This issue affects Juniper Networks Junos OS: * All versions earlier than 20.4R3-S8; * 21.1 versions earlier than 21.1R3-S4; * 21.2 versions earlier than 21.2R3-S6; * 21.3 versions earlier than 21.3R3-S3; * 21.4 versions earlier than 21.4R3-S5; * 22.1 versions earlier than 22.1R2-S2, 22.1R3; * 22.2 versions earlier than 22.2R2-S1, 22.2R3.
This is a reflected cross site scripting vulnerability in the PaperCut NG/MF application server. An attacker can exploit this weakness by crafting a malicious URL that contains a script. When an unsuspecting user clicks on this malicious link, it could potentially lead to limited loss of confidentiality, integrity or availability.
Improper Neutralization of Equivalent Special Elements in GitHub repository btcpayserver/btcpayserver prior to 1.8.0.
Improper Neutralization of Equivalent Special Elements in GitHub repository btcpayserver/btcpayserver prior to 1.7.5.
Ta podatność potencjalnie umożliwia ujawnienie plików na serwerze PaperCut NG/MF przy użyciu specjalnie przygotowanego payload'u skierowanego na narażony endpoint API. Osoba atakująca musi przeprowadzić rekonesans, aby uzyskać wiedzę na temat system token. Ta CVE dotyczy wyłącznie serwerów PaperCut NG/MF na Linux i macOS.