Vagrant Synced Folder Vagrantfile Breakout...

- AV AC AU C I A
发布: 2022-10-27
修订: 2024-12-11

This Metasploit module exploits a default Vagrant synced folder (shared folder) to append a Ruby payload to the Vagrant project Vagrantfile config file. By default, unless a Vagrant project explicitly disables shared folders, Vagrant mounts the project directory on the host as a writable vagrant directory on the guest virtual machine. This directory includes the project Vagrantfile configuration file. Ruby code within the Vagrantfile is loaded and executed when a user runs any vagrant command from the project directory on the host, leading to execution of Ruby code on the host.

0%
当前有1条漏洞利用/PoC
当前有0条受影响产品信息