Dockwatch Remote Command Execution...

- AV AC AU C I A
发布: 2024-09-17
修订: 2025-07-26

Dockwatch is a container management web UI for docker. It runs by default without authentication, although guidance is available for how to setup credentials for access. It has a Commands feature that allows a user to run docker commands such as inspect, network, ps. Prior to fix, it did not restrict input for parameters, so both container and parameters for the dockerInspect command were vulnerable to shell command injection on the container as the abc user with (limited) command output. See commits 23df366 and c091e4c for fixes.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息