RULE(RULE ID:338470)

Rule General Information
Release Date: 2024-10-15
Rule Name: Chaosblade 1.7.3 Remote Command Execution Vulnerability (CVE-2023-47105)
Severity:
CVE ID:
Rule Protection Details
Description: Chaosblade 1.7.3 remote command execution vulnerability (cve-2023-47105).
Impact: An attacker can execute arbitrary command via a successful exploit in the context of the vulnerable software.
Affected OS: Windows, Linux, Others
Reference: https://github.com/chaosblade-io/chaosblade/blob/0a07380c9899febb2b544132783b376b44226cca/exec/os/executor.go
https://narrow-oatmeal-0c0.notion.site/ChaosBlade-Remote-Command-Execution-CVE-2023-47105-4f5459046488436caaec2bced6ff26d7
https://cxsecurity.com/cveshow/CVE-2023-47105/
Solutions
Refer to the announcement or patch by the vendor: https://github.com/chaosblade-io/chaosblade/releases/tag/v1.7.4