exec.CommandContext in Chaosblade 0.3 through 1.7.3, when server mode is used, allows OS command execution via the cmd parameter without authentication.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| github.com/chaosblade-io/chaosblade(Go) | 0.0.3 | 1.7.4 | N/A |
CVSS Metrics