CVE-2024-24890

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in openEuler gala-gopher on Linux allows Command Injection. This vulnerability is associated with program files https://gitee.Com/openeuler/gala-gopher/blob/master/src/probes/extends/ebpf.Probe/src/ioprobe/ioprobe.C. This issue affects gala-gopher: through 1.0.2.
Configurations

No configuration.

History

21 Nov 2024, 08:59

Type Values Removed Values Added
References () https://gitee.com/src-openeuler/gala-gopher/pulls/81 - () https://gitee.com/src-openeuler/gala-gopher/pulls/81 -
References () https://gitee.com/src-openeuler/gala-gopher/pulls/82 - () https://gitee.com/src-openeuler/gala-gopher/pulls/82 -
References () https://gitee.com/src-openeuler/gala-gopher/pulls/85 - () https://gitee.com/src-openeuler/gala-gopher/pulls/85 -
References () https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2024-1277 - () https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2024-1277 -
References () https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2024-1278 - () https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2024-1278 -
References () https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2024-1279 - () https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2024-1279 -

25 Mar 2024, 13:47

Type Values Removed Values Added
Summary
  • (es) La neutralización inadecuada de elementos especiales utilizados en una vulnerabilidad de comando del sistema operativo ('inyección de comando del sistema operativo') en openEuler gala-gopher en Linux permite la inyección de comando. Esta vulnerabilidad está asociada con archivos de programa https://gitee.Com/openeuler/gala-gopher/blob/master/src/probes/extends/ebpf.Probe/src/ioprobe/ioprobe.C. Este problema afecta a gala-gopher: hasta 1.0.2.

25 Mar 2024, 07:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-03-25 07:15

Updated : 2024-11-21 08:59


NVD link : CVE-2024-24890

Mitre link : CVE-2024-24890

CVE.ORG link : CVE-2024-24890


JSON object : View

Products Affected

No product.

CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')