Security

CVE-2023-31039

qianmoQqianmoQ· 更新于 2026-10-04· 阅读 3 分钟· 0 次阅读

登录后可跨设备保存划线和私人笔记登录

CVE-2023-31039

CVE-2023-31039: ServerOptions.pid_file may cause arbitrary code execution

Severity: Important

Affected Versions: Apache bRPC 0.9.0 before 1.5.0

Description: Security vulnerability in Apache bRPC <1.5.0 on all platforms allows attackers to execute arbitrary code via ServerOptions::pid_file. An attacker that can influence the ServerOptions pid_file parameter with which the bRPC server is started can execute arbitrary code with the permissions of the bRPC process.

Solution:

Required Configurations:

  • set brpc::pid_file from user input

Work Arounds:

References:

  1. https://brpc.apache.org
  2. https://www.cve.org/CVERecord?id=CVE-2023-31039

Last modified May 16, 2023: add security bug fix pages (devlive-community/knowforge#148) (a29da9f83)

评论

登录后参与评论

正在加载评论…