ilbers / isar

Integration System for Automated Root filesystem generation
Other
177 stars 72 forks source link

Memcached Injection #58

Closed QiAnXinCodeSafe closed 3 years ago

QiAnXinCodeSafe commented 5 years ago

We found a problem about Memcached Injection in isar-master/bitbake/lib/toaster/toastergui/typeaheads.py image Invoking a Memcached operation with input coming from an untrusted source might allow an attacker to introduce new key/value pairs in Memcached cache.

ismagulb commented 5 years ago

Thanks for the report, we'll have a look.

ismagulb commented 3 years ago

bitbake is a copy of an external package, the issue must be addressed there.