Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Kahua before 0.7, when running multiple applications under a single supervisor, grants application access on the basis of username instead of username and database name, which allows remote authenticated users to obtain unauthorized access if different databases assign the same username to different user accounts.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Kahua 权限认证和访问控制漏洞
Vulnerability Description
Kahua的0.7之前版本,在单个监管者下运行多个应用程序时,基于用户名而非用户名和数据库名来授予应用程序访问权,如果不同数据库给不同用户账户分配了同样的用户名则远程认证用户可以获取未授权的访问。
CVSS Information
N/A
Vulnerability Type
N/A