PT-2024-20651 · Openeuler · Openeuler+1

Published

2024-03-15

·

Updated

2024-03-26

·

CVE-2024-24899

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions openEuler aops-zeus versions 1.2.0 through 1.4.0
Description The issue is related to an Improper Neutralization of Special Elements used in an OS Command, also known as 'OS Command Injection', which allows Command Injection. This problem is associated with program files, specifically https://gitee.Com/openeuler/aops-zeus/blob/master/zeus/conf/constant.Py.
Recommendations For versions 1.2.0 through 1.4.0, consider disabling the functionality related to the constant.Py file until a patch is available. Restrict access to the vulnerable module to minimize the risk of exploitation. Avoid using the affected API endpoints or parameters that may lead to Command Injection until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2024-24899
OESA-2024-1291
OESA-2024-1292
OESA-2024-1293
OESA-2024-1294

Affected Products

Aops-Zeus
Openeuler