CVE-2023-47105 Information

Description

exec.CommandContext in Chaosblade 0.3 through 1.7.3 when server mode is used allows OS command execution via the cmd parameter without authentication.

Reference

https://github.com/chaosblade-io/chaosblade/blob/0a07380c9899febb2b544132783b376b44226cca/exec/os/executor.go#L68 https://narrow-oatmeal-0c0.notion.site/ChaosBlade-Remote-Command-Execution-CVE-2023-47105-4f5459046488436caaec2bced6ff26d7

Share on: