Closed SuperXiaoxiong closed 7 years ago
All I know vault.dump make the input_data to be a string in the yaml_text, and the result of it also is a string , but the pwned.txt you give can be executed in the version 1.0.4 I wonder how to make txt just like the pwned.txt thks very much!
@SuperXiaoxiong It descrived in CVE-2017-2809 and TALOS-2017-0305. See there.
All I know vault.dump make the input_data to be a string in the yaml_text, and the result of it also is a string , but the pwned.txt you give can be executed in the version 1.0.4 I wonder how to make txt just like the pwned.txt thks very much!