PT-2026-21750 · Bleon Ethical · Api-Gateway-Deploy
Bleon-Ethical
·
Publicado
2026-02-24
·
Atualizado
2026-03-01
·
CVE-2026-27208
CVSS v3.1
9.2
Crítica
| Vetor | AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:H |
Name of the Vulnerable Software and Affected Versions
bleon-ethical/api-gateway-deploy version 1.0.0
Description
The software is susceptible to an attack chain involving OS Command Injection and Privilege Escalation. Successful exploitation allows an attacker to execute arbitrary commands with root privileges within the container, potentially leading to a container escape and unauthorized infrastructure modifications. The issue is related to insufficient input validation and insecure configurations.
Recommendations
Update to version 1.0.1, which includes fixes such as strict input sanitization and secure delimiters in the
entrypoint.sh file, enforcement of a non-root user (appuser) in the Dockerfile, and mandatory security quality gates.Exploit
Correção
LPE
Argument Injection
OS Command Injection
Improper Privilege Management
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Api-Gateway-Deploy