Authenticated Gaia users can inject code or commands by global variables through special HTTP requests. A Security fix that mitigates this vulnerability is available.
The product does not properly restrict reading from or writing to dynamically-identified variables.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Gaia_os | Checkpoint | r81 (including) | r81 (including) |
Gaia_os | Checkpoint | r81.10 (including) | r81.10 (including) |
Gaia_os | Checkpoint | r81.20 (including) | r81.20 (including) |