We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
Aviatrix Controller versions prior to 7.1.4208, 7.2.5090, and 8.0.0 fail to sanitize user input prior to passing the input to command line utilities, allowing command injection via special characters in filenames
Reserved 2025-03-10 | Published 2025-06-23 | Updated 2025-06-23 | Assigner MandiantCWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
github.com/...Disclosures/blob/master/2025/MNDT-2025-0004.md
cloud.google.com/...emote-code-execution-aviatrix-controller
Support options