PT-2021-15141 · Google · Slo Generator
Cimihan123
+1
·
Published
2021-10-04
·
Updated
2022-10-25
·
CVE-2021-22557
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
SLO Generator versions prior to the version including https://github.com/google/slo-generator/pull/173
Description
The SLO generator has an issue where it allows for the loading of YAML files. If these files are crafted in a specific format, they can enable code execution within the context of the SLO Generator.
Recommendations
Upgrade SLO Generator past the version including https://github.com/google/slo-generator/pull/173. As a temporary workaround, consider restricting the loading of YAML files or ensuring they are thoroughly validated before use to minimize the risk of exploitation.
Exploit
Fix
Code Injection
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Slo Generator