Server side template injection In shadowsocks-libev
Description
In manager.c in ss-manager in shadowsocks-libev 3.1.0, improper parsing allows command injection via shell metacharacters in a JSON configuration request received via 127.0.0.1 UDP traffic, related to the add_server, build_config, and construct_command_line functions.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
debian 14 | 3.1.0+ds-2 | ||
debian 13 | 3.1.0+ds-2 | ||
debian 11 | 3.1.0+ds-2 | ||
debian 12 | 3.1.0+ds-2 |
Aliases
1. 2. 3. 4. 5.