View in Telegram
盐酸乙酰胆碱
CVE-2024-54143 An attacker can compromise the build artifact delivered from the
sysupgrade.openwrt.org
, allowing the malicious firmware image to be installed to the OpenWrt installation that uses the attended firmware upgrade,
firmware-selector.openwrt.org
, or CLI upgrade.
https://github.com/openwrt/asu/security/advisories/GHSA-r3gq-96h6-3v7q
GitHub
Build artifact poisoning via truncated SHA-256 hash and command injection
## Summary
Due to the combination of the command injection in the `openwrt/imagebuilder` image and the truncated SHA-256 hash included in the build request hash, an attacker can pollute the legi...
Share
Love Center - Dating, Friends & Matches, NY, LA, Dubai, Global
Find friends or serious relationships easily
Start