CVE-2024-24899

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in openEuler aops-zeus on Linux allows Command Injection. This vulnerability is associated with program files https://gitee.Com/openeuler/aops-zeus/blob/master/zeus/conf/constant.Py. This issue affects aops-zeus: from 1.2.0 through 1.4.0.
Configurations

No configuration.

History

21 Nov 2024, 08:59

Type Values Removed Values Added
References () https://gitee.com/src-openeuler/aops-zeus/pulls/107 - () https://gitee.com/src-openeuler/aops-zeus/pulls/107 -
References () https://gitee.com/src-openeuler/aops-zeus/pulls/108 - () https://gitee.com/src-openeuler/aops-zeus/pulls/108 -
References () https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2024-1291 - () https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2024-1291 -
References () https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2024-1292 - () https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2024-1292 -
References () https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2024-1293 - () https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2024-1293 -
References () https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2024-1294 - () https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2024-1294 -

25 Mar 2024, 13:47

Type Values Removed Values Added
Summary
  • (es) La neutralización inadecuada de elementos especiales utilizados en una vulnerabilidad de comando del sistema operativo ('inyección de comando del sistema operativo') en openEuler aops-zeus en Linux permite la inyección de comando. Esta vulnerabilidad está asociada con archivos de programa https://gitee.Com/openeuler/aops-zeus/blob/master/zeus/conf/constant.Py. Este problema afecta a aops-zeus: desde 1.2.0 hasta 1.4.0.

25 Mar 2024, 07:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-03-25 07:15

Updated : 2024-11-21 08:59


NVD link : CVE-2024-24899

Mitre link : CVE-2024-24899

CVE.ORG link : CVE-2024-24899


JSON object : View

Products Affected

No product.

CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')